An unintended or unauthorized intra-system channel that enables two cooperating entities to transfer information in a way that violates the system's security policy but does not exceed the entities' access authorizations.
Source(s):
CNSSI 4009-2015
from
IETF RFC 4949 Ver 2
NIST SP 800-53 Rev. 5
from
CNSSI 4009-2015