Cyber Posture

CWE · MITRE source

CWE-300Channel Accessible by Non-Endpoint

Abstraction: Class · CVEs in our corpus: 53

The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.

In order to establish secure communication between two parties, it is often important to adequately verify the identity of entities at each end of the communication channel. Inadequate or inconsistent verification may result in insufficient or incorrect identification of either communicating entity. This can have negative consequences such as misplaced trust in the entity at the other end of the channel. An attacker can leverage this by interposing between the communicating entities and masquerading as the original entity. In the absence of sufficient verification of identity, such an attacker can eavesdrop and potentially modify the communication between the original entities.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (11)AI

Showing the 6 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
SC-11Trusted PathSCExplicitly isolates the communications path so it cannot be accessed or intercepted by non-endpoint entities during security functions.
SC-19Voice Over Internet ProtocolSCRestrictions and channel controls reduce the chance that VoIP media or signaling streams remain accessible to non-participants.
SC-23Session AuthenticitySCDirectly prevents non-endpoint access or interception of the session communication path.
IA-3Device Identification and AuthenticationIAEnsures only authenticated endpoints can access the communication channel, blocking unauthorized non-endpoint access.
PE-4Access Control for TransmissionPEPhysically restricts transmission channels so they cannot be accessed or tapped by non-endpoint actors within facilities.
RA-6Technical Surveillance Countermeasures SurveyRAPeriodic TSCM surveys identify unauthorized access points or taps that make communication channels reachable by non-endpoint adversaries.
Show 5 more broadly-applicable controls
SC-37Out-of-band ChannelsSCAn out-of-band channel is inaccessible to non-endpoints that can observe or interfere with the primary communication channel.
SC-40Wireless Link ProtectionSCThe control restricts an inherently broadcast wireless channel to only intended endpoints, mitigating accessibility by non-endpoints.
SC-41Port and I/O Device AccessSCEliminates channels that could be accessed by non-endpoint actors through disabled ports and devices.
SC-8Transmission Confidentiality and IntegritySCConfidentiality and integrity protections on the transmission channel directly reduce the ability of non-endpoint actors to access or tamper with the data.
SC-9Transmission ConfidentialitySCRenders the transmission channel inaccessible to non-endpoint eavesdroppers through encryption, eliminating the weakness class.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-121502.77.40.19902018-07-26
CVE-2017-74802.19.80.02142017-07-21
CVE-2019-37932.09.80.00252019-04-24
CVE-2017-121511.77.40.04152018-07-27
CVE-2023-310041.78.30.00132024-02-03
CVE-2019-54561.68.10.00362019-07-30
CVE-2021-410331.68.10.00432021-09-13
CVE-2021-219531.68.10.00312021-12-22
CVE-2023-326341.67.80.00032023-10-12
CVE-2024-312061.68.20.00042024-04-04
CVE-2024-365531.68.10.00092025-02-06
CVE-2025-201221.67.80.00062025-05-07
CVE-2025-312141.68.10.00272025-05-12
CVE-2017-68701.57.40.00242017-08-08
CVE-2017-99411.57.40.00192017-08-08
CVE-2017-127351.57.40.00242017-08-30
CVE-2017-150861.57.40.00262017-11-08
CVE-2019-148991.57.40.00052019-12-11
CVE-2020-107491.56.00.05192020-06-03
CVE-2021-229091.57.50.00562021-05-27
CVE-2021-329261.57.50.00132021-06-03
CVE-2024-320491.57.40.00432024-05-08
CVE-2025-407701.57.40.00022025-08-12
CVE-2025-633631.57.50.00072025-12-04
CVE-2019-00541.46.80.00082019-10-09