RE: Cross-configuration attacks

2021-09-24 Thread John Thomas
also relevant for defense-in-depth). Is there a CWE for ambiguity in security protocols between multiple parties? With regards, John Thomas From: Kurt Seifried Sent: Thursday, September 23, 2021 11:20 PM To: noloa...@gmail.com Cc: cwe-research-l...@lists.mitre.org Subject: Re: Cross

CWE 129 - Example 3

2021-09-24 Thread John Thomas
le (I've noticed CWE-125, CWE-129 and CWE 839 using this example, but I would not be surprised if other instances are as well) Does my suggested change make sense? Again, please correct me if this is the wrong forum to suggest this change. With regards, John Thomas Field Application Engineer Technical Lead LDRA Technology