CWE Database
/

CWE-940

Back to CWE list

CWE-940

Improper Verification of Source of a Communication Channel

Base
Incomplete

Description

The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.

When an attacker can successfully establish a communication channel from an untrusted origin, the attacker may be able to gain privileges and access unexpected functionality.

Common Consequences

Scope

Access Control
Other

Impact

Gain Privileges or Assume Identity, Varies by Context, Bypass Protection Mechanism

Potential Mitigations

Architecture and Design

Use a mechanism that can validate the identity of the source, such as a certificate, and validate the integrity of data to ensure that it cannot be modified in transit using an Adversary-in-the-Middle (AITM) attack. When designing functionality of actions in the URL scheme, consider whether the action should be accessible to all mobile applications, or if an allowlist of applications to interface with is appropriate.

CVE-2025-3651

desktop product does not properly verify the source of a communication channel, allowing command execution

CVE-2000-1218

DNS server can accept DNS updates from hosts that it did not query, leading to cache poisoning

CVE-2005-0877

DNS server can accept DNS updates from hosts that it did not query, leading to cache poisoning

CVE-2001-1452

DNS server caches glue records received from non-delegated name servers

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now