CWE-421Base

Race Condition During Access to Alternate Channel

Draft in the CWE catalog · 7 CVEs mapped

7
CVEs mapped
6.5
Median CVSS
What it is

The product opens an alternate channel to communicate with an authorized user, but the channel is accessible to other actors.

Recent examples
7.5cvss
CVE-2023-32256

Kernel: ksmbd race issue from smb2 close and logoff with multichannel

A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in multichannel connections could result in a use-after-free issue.

HIGHno explanation yet
1%
epss
4.3cvss
CVE-2023-40536

Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable…

Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

MEDIUMno explanation yet
0%
epss
1.8cvss
CVE-2023-41090

Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escalation of privilege via local access

Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escalation of privilege via local access.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-421
Abstraction
Base
Structure
Simple
Status
Draft
References (1)