CWE-1250: Improper Preservation of Consistency Between Independent Representations of Shared State

BaseIncomplete

The product has or supports multiple distributed components or sub-systems that are each required to keep their own local copy of shared data - such as state or cache - but the product does not ensure that all local copies remain consistent with each other.

View on MITRE
Back to CWE Lookup

Extended Description

In highly distributed environments, or on systems with distinct physical components that operate independently, there is often a need for each component to store and update its own local copy of key data such as state or cache, so that all components have the same "view" of the overall system and operate in a coordinated fashion. For example, users of a social media service or a massively multiplayer online game might be using their own personal computers while also interacting with different physical hosts in a globally distributed service, but all participants must be able to have the same "view" of the world. Alternately, a processor's Memory Management Unit (MMU) might have "shadow" MMUs to distribute its workload, and all shadow MMUs are expected to have the same accessible ranges of memory. In such environments, it becomes critical for the product to ensure that this "shared state" is consistently modified across all distributed systems. If state is not consistently maintained across all systems, then critical transactions might take place out of order, or some users might not get the same data as other users. When this inconsistency affects correctness of operations, it can introduce vulnerabilities in mechanisms that depend on consistent state.

Technical Details

Structure
Simple
Vulnerability Mapping
ALLOWED

Applicable To

Languages
Not Language-Specific
Platforms
Not OS-Specific

Source-backed guidance

Additional facts reviewed against primary or authoritative security sources.

Detect imprecise mappings involving CWE-1250

Review mappings to CWE-1250, Improper Preservation of Consistency Between Independent Representations of Shared State, with MITRE's mapping and navigation criteria. Flag any selection that points to a View or Category, remains at a higher abstraction than the available evidence supports, or ignores relevant parent, child, peer, and alternative entries. Treat those findings as mapping-quality defects, correct them before publication, and retain the comparison trail for repeatable audits.

CWE Mapping and Navigation GuidanceMITRE CWE

Prevent CWE-1250 through an SSDF control plan

Use NIST SSDF practices to make prevention of CWE-1250, Improper Preservation of Consistency Between Independent Representations of Shared State, an explicit development outcome. Translate the CWE definition into security requirements and design constraints, choose safer implementation patterns and toolchain checks, and define acceptance evidence before release. Feed every confirmed occurrence back into the requirements, design review, and coding rules so the same root cause is removed across the product rather than patched in one location.

NIST SP 800-218 Secure Software Development FrameworkNational Institute of Standards and Technology

Triage CWE-1250 against known exploitation evidence

Use CISA's Known Exploited Vulnerabilities catalog to test whether a vulnerability mapped to CWE-1250, Improper Preservation of Consistency Between Independent Representations of Shared State, has evidence of exploitation in the wild. Confirm the CVE-to-CWE root-cause mapping independently before attaching the example, then capture the affected product, required action, and remediation deadline. A missing KEV match is not evidence that the weakness is unexploited, and a KEV entry must not be generalized to every occurrence of this CWE.

Known Exploited Vulnerabilities CatalogCybersecurity and Infrastructure Security Agency

Use MITRE taxonomy anchors to review Improper Preservation of Consistency Between Independent Representations of Shared State

Recorded impacts include Unexpected State; related weaknesses include CWE-664; applicable implementation contexts include Security Hardware. Use these source-defined anchors to turn CWE-1250 into implementation, review, and verification checks for the affected component.

CWE-1250: Improper Preservation of Consistency Between Independent Representations of Shared StateMITRE CWE

Validate CWE-1250 with root-cause mapping checks

Apply MITRE's root-cause mapping quick tips to CWE-1250, Improper Preservation of Consistency Between Independent Representations of Shared State. Confirm the finding describes the causal weakness rather than an impact or attack pattern, compare the abstraction and mapping notes with plausible alternatives, and have a second reviewer challenge the selection. Preserve the evidence and reasoning so recurring defects can be measured against one consistent identifier.

CVE to CWE Root Cause Mapping Quick TipsMITRE CWE

Frequently Asked Questions

What is CWE-1250: Improper Preservation of Consistency Between Independent Representations of Shared State?+

CWE-1250: Improper Preservation of Consistency Between Independent Representations of Shared State is a Common Weakness Enumeration (CWE) entry maintained by MITRE. The product has or supports multiple distributed components or sub-systems that are each required to keep their own local copy of shared data - such as state or cache - but the product does not ensure that all local copies remain consistent with each other. In highly distributed environments, or on systems with distinct physical components that operate independently, there is often a need for each component to store and update its own local copy of key data such as state or cache, so that all components have the same "view" of the overall system and operate in a coordinated fashion. For example, users of a social media service or a massively multiplayer online game might be using their own personal computers while also interacting with different physical hosts in a globally distributed service, but all participants must be able to have the same "view" of the world. Alternately, a processor's Memory Management Unit (MMU) might have "shadow" MMUs to distribute its workload, and all shadow MMUs are expected to have the same accessible ranges of memory. In such environments, it becomes critical for the product to ensure that this "shared state" is consistently modified across all distributed systems. If state is not consistently maintained across all systems, then critical transactions might take place out of order, or some users might not get the same data as other users. When this inconsistency affects correctness of operations, it can introduce vulnerabilities in mechanisms that depend on consistent state.

What are the security consequences of Improper Preservation of Consistency Between Independent Representations of Shared State?+

If exploited, CWE-1250 (Improper Preservation of Consistency Between Independent Representations of Shared State) it can compromise Other, leading to outcomes such as Unexpected State.

Which programming languages are affected by Improper Preservation of Consistency Between Independent Representations of Shared State?+

CWE-1250 commonly affects Not Language-Specific. Note that weaknesses are often language-agnostic patterns, so secure coding practices apply broadly.

What is the difference between a CWE and a CVE?+

A CWE (Common Weakness Enumeration) like CWE-1250 describes a category of software weakness — the underlying flaw type. A CVE (Common Vulnerabilities and Exposures) identifies a specific, real-world vulnerability in a particular product. In short, a CWE is the kind of mistake, and a CVE is an instance of that mistake being found in software.

Learn More

Advertisement