[EXT] Re: Cross-configuration attacks

2021-09-24 Thread Fredrick Omeniho
__ > From: Kurt Seifried > Sent: Friday, September 24, 2021 10:08 AM > To: Steven M Christey > Cc: Walton, Jeffrey; CWE Research Discussion > Subject: Re: Cross-configuration attacks > > > > On Thu, Sep 23, 2021 at 11:02 PM Steven M C

Re: Cross-configuration attacks

2021-09-24 Thread Kerry Crouse
4, 2021 10:08 AM To: Steven M Christey Cc: Walton, Jeffrey; CWE Research Discussion Subject: Re: Cross-configuration attacks On Thu, Sep 23, 2021 at 11:02 PM Steven M Christey mailto:co...@mitre.org>> wrote: Just a couple quick comments since it’s late for me :) CWE-435: Improper Int

RE: Cross-configuration attacks

2021-09-24 Thread Kanuparthi, Arun
are fine by themselves, but there can be weaknesses in a parent component that instantiates both the blocks. Thanks, Arun From: Kurt Seifried Sent: Thursday, September 23, 2021 8:20 PM To: noloa...@gmail.com Cc: cwe-research-l...@lists.mitre.org Subject: Re: Cross-configuration attacks I assum

Re: Cross-configuration attacks

2021-09-24 Thread Kurt Seifried
t; > *From:* Kurt Seifried > *Sent:* Thursday, September 23, 2021 11:20 PM > *To:* Walton, Jeffrey > *Cc:* CWE Research Discussion > *Subject:* Re: Cross-configuration attacks > > > > I assume by CVE you meant CWE, and no there isn't a CWE for "intersection"

RE: Cross-configuration attacks

2021-09-24 Thread Paul.Wortman
. - Paul From: John Thomas Sent: Friday, September 24, 2021 8:22 AM To: Kurt Seifried ; noloa...@gmail.com Cc: cwe-research-l...@lists.mitre.org Subject: RE: Cross-configuration attacks I think the issue here is the ambiguity in the behavior. If App A knows App B’s behavior fully and with no

RE: Cross-configuration attacks

2021-09-24 Thread Steven M Christey
Sent: Friday, September 24, 2021 4:28:07 AM To: Steven M Christey mailto:co...@mitre.org>> Cc: Seifried, Kurt mailto:k...@seifried.org>>; Walton, Jeffrey mailto:noloa...@gmail.com>>; CWE Research Discussion mailto:cwe-research-list@mitre.org>> Subject: Re: Cross-configuratio

Re: Cross-configuration attacks

2021-09-24 Thread Steve Battista
even M Christey Cc: Seifried, Kurt ; Walton, Jeffrey ; CWE Research Discussion Subject: Re: Cross-configuration attacks About configurations, I’m still scratching my head about where PrintNightmare’s “Insecure by design” would fall (fail?). Best, Sebastian On Sep 24, 2021, at 1:01 AM, St

RE: Cross-configuration attacks

2021-09-24 Thread John Thomas
also relevant for defense-in-depth). Is there a CWE for ambiguity in security protocols between multiple parties? With regards, John Thomas From: Kurt Seifried Sent: Thursday, September 23, 2021 11:20 PM To: noloa...@gmail.com Cc: cwe-research-l...@lists.mitre.org Subject: Re: Cross

Re: Cross-configuration attacks

2021-09-24 Thread SebastianGanson
t; > From: Kurt Seifried > Sent: Thursday, September 23, 2021 11:20 PM > To: Walton, Jeffrey > Cc: CWE Research Discussion > Subject: Re: Cross-configuration attacks > > I assume by CVE you meant CWE, and no there isn't a CWE for "intersection" or &g

RE: Cross-configuration attacks

2021-09-23 Thread Steven M Christey
23, 2021 11:20 PM To: Walton, Jeffrey Cc: CWE Research Discussion Subject: Re: Cross-configuration attacks I assume by CVE you meant CWE, and no there isn't a CWE for "intersection" or "mismatch" attacks. I don't like the term cross-configuration unless it's

Re: Cross-configuration attacks

2021-09-23 Thread Kurt Seifried
I assume by CVE you meant CWE, and no there isn't a CWE for "intersection" or "mismatch" attacks. I don't like the term cross-configuration unless it's actually applied to issues that are created by configuration issues, my concern would be technically any intersection vulnerability can be classed