CWE-340: Predictability Problems
Weakness ID: 340 (Weakness Class) Status: Incomplete
Description
Description Summary
Weaknesses in this category are related to schemes that generate numbers or identifiers that are more predictable than required by the application.
Time of Introduction
Architecture and Design
Implementation
Common Consequences
Scope Effect
Other
Technical Impact: Varies by context
Relationships
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Predictability problems
WASC 11 Brute Force
References
[REF-17] Michael Howard, David LeBlanc
and John Viega. "24 Deadly Sins of Software Security". "Sin 20: Weak Random Numbers." Page 299. McGraw-Hill. 2010.
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time_of_Introduction 2008-09-08 CWE Content Team MITRE Internal updated Relationships,
Taxonomy_Mappings 2010-02-16 CWE Content Team MITRE Internal updated Taxonomy_Mappings 2011-06-01 CWE Content Team MITRE Internal updated Common_Consequences 2011-06-27 CWE Content Team MITRE Internal updated Common_Consequences 2012-05-11 CWE Content Team MITRE Internal updated References, Relationships