CWE-420: Unprotected Alternate Channel
The product protects a primary channel, but it does not use the same level of protection for an alternate channel.
Last updated
Overview
CWE-420 (Unprotected Alternate Channel) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
36 recorded CVEs are caused by CWE-420 (Unprotected Alternate Channel), including 2 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 7 new CWE-420 CVEs have been recorded so far in 2026 (13 in 2025).