Skip to content

CWE-351: Insufficient Type Distinction

AbstractionStructureStatus
NoneSimpleDraft

Description

The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.

NatureIDView IDName
ChildOfCWE-3451000Insufficient Verification of Data Authenticity
PeerOfCWE-4361000Interpretation Conflict

Modes of Introduction

PhaseNote
Implementation-

Applicable Platforms

Languages

Class: Not Language-Specific

Technologies

Common Consequences

ScopeImpactNote
OtherOther

Observed Examples

  • CVE-2005-2260: Browser user interface does not distinguish between user-initiated and synthetic events.
  • CVE-2005-2801: Product does not compare all required data in two separate elements, causing it to think they are the same, leading to loss of ACLs. Similar to Same Name error.