CWE-291: Reliance on IP Address for Authentication
The product uses an IP address for authentication.
How it's found
Reliance on IP Address for Authentication is a specific, narrowly defined instance of a broader pattern. Testers confirm it with targeted code review and a proof-of-concept input that exercises the exact code path this weakness describes.
IP addresses can be easily spoofed. Attackers can forge the source IP address of the packets they send, but response packets will return to the forged IP address. To see the response packets, the attacker has to sniff the traffic between the victim machine and the forged IP address. In order to accomplish the required sniffing, attackers typically attempt to locate themselves on the same subnet as the victim machine. Attackers may be able to circumvent this requirement by using source routing, but source routing is disabled across much of the Internet today. In summary, IP address verification can be a useful part of an authentication scheme, but it should not be the single factor required for authentication.
Consequences
- Hide Activities, Gain Privileges or Assume Identity: Malicious users can fake authentication information, impersonating any IP address.
Mitigations
- Architecture and Design: Use other means of identity verification that cannot be simply spoofed. Possibilities include a username/password or certificate.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is CWE-291?
The product uses an IP address for authentication.
How do you find Reliance on IP Address for Authentication?
Reliance on IP Address for Authentication is a specific, narrowly defined instance of a broader pattern. Testers confirm it with targeted code review and a proof-of-concept input that exercises the exact code path this weakness describes.
What is the impact of CWE-291?
Hide Activities, Gain Privileges or Assume Identity: Malicious users can fake authentication information, impersonating any IP address.
Does TurboPentest test for Reliance on IP Address for Authentication?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related CWEs
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest