CWE-636: Failing Open
Not Failing Securely
When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
How it's found
Failing Open describes a general pattern rather than a single fixed bug. Testers use a mix of static analysis and manual code review to find where a target's code matches this pattern, then confirm exploitability by hand.
By entering a less secure state, the product inherits the weaknesses associated with that state, making it easier to compromise. At the least, it causes administrators to have a false sense of security. This weakness typically occurs as a result of wanting to "fail functional" to minimize administration and support costs, instead of "failing safe."
Consequences
- Bypass Protection Mechanism: Intended access restrictions can be bypassed, which is often contradictory to what the product's administrator expects.
Mitigations
- Architecture and Design: Subdivide and allocate resources and components so that a failure in one part does not affect the entire product.
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is CWE-636?
When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
How do you find Failing Open?
Failing Open describes a general pattern rather than a single fixed bug. Testers use a mix of static analysis and manual code review to find where a target's code matches this pattern, then confirm exploitability by hand.
What is the impact of CWE-636?
Bypass Protection Mechanism: Intended access restrictions can be bypassed, which is often contradictory to what the product's administrator expects.
Does TurboPentest test for Failing Open?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related CWEs
- Class weaknessCWE-657: Violation of Secure Design Principles
- Class weaknessCWE-755: Improper Handling of Exceptional Conditions
- Base weaknessCWE-280: Improper Handling of Insufficient Permissions or Privileges
- Base weaknessCWE-203: Observable Discrepancy
- Base weaknessCWE-209: Generation of Error Message Containing Sensitive Information
- Class weaknessCWE-228: Improper Handling of Syntactically Invalid Structure
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest