The product opens an alternate channel to communicate with an authorized user, but the channel is accessible to other actors.
Volume of CVEs assigned to CWE-421 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32256HIGH A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in multichannel connections could result in a use-after-free issue. | Aug 1, 2025 | 7.5 | 28 | NO | NO |
CVE-2023-43687MEDIUM An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). There is a Race condition that leads to code execution because of | Aug 14, 2025 | 6.5 | 22 | NO | NO |
CVE-2023-34438HIGH Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | Aug 11, 2023 | 7.8 | 21 | NO | NO |
CVE-2023-41090MEDIUM Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escalation of privilege via local access. | Feb 14, 2024 | 6.4 | 19 | NO | NO |
CVE-2023-34349MEDIUM Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | Aug 11, 2023 | 6.4 | 18 | NO | NO |
CVE-2023-40536MEDIUM Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via a | May 16, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-22310MEDIUM Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access. | Nov 14, 2023 | 4.7 | 15 | NO | NO |
CVE-2023-22276MEDIUM Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of se | Aug 11, 2023 | 4.7 | 15 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.