CWE Database
/

CWE-421

Back to CWE list

CWE-421

Race Condition During Access to Alternate Channel

Base
Draft

Description

The product opens an alternate channel to communicate with an authorized user, but the channel is accessible to other actors.

This creates a race condition that allows an attacker to access the channel before the authorized user does.

Common Consequences

Scope

Access Control

Impact

Gain Privileges or Assume Identity, Bypass Protection Mechanism

CVE-1999-0351

FTP "Pizza Thief" vulnerability. Attacker can connect to a port that was intended for use by another client.

CVE-2003-0230

Product creates Windows named pipe during authentication that another attacker can hijack by connecting to it.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now