CWE-358: Improperly Implemented Security Check for Standard
Improperly Implemented Security Check for Standard
Weakness ID: 358 (Weakness Base)
Status: Draft
Description
Description Summary
The software does not implement or incorrectly implements one
or more security-relevant checks as specified by the design of a standardized
algorithm, protocol, or technique.
Time of Introduction
Architecture and Design
Implementation
Applicable Platforms
Languages
All
Modes of Introduction
This is an implementation error, in which the algorithm/technique requires
certain security-related behaviors or conditions that are not implemented or
checked properly, thus causing a vulnerability.
This is a "missing step" error on the product side, which can overlap
weaknesses such as insufficient verification and spoofing. It is frequently
found in cryptographic and authentication errors. It is sometimes
resultant.
Taxonomy Mappings
Mapped Taxonomy Name
Node ID
Fit
Mapped Node Name
PLOVER
Improperly Implemented Security Check for
Standard
Content History
Submissions
Submission Date
Submitter
Organization
Source
PLOVER
Externally Mined
Modifications
Modification Date
Modifier
Organization
Source
2008-07-01
Eric Dalci
Cigital
External
updated Time of Introduction
2008-09-08
CWE Content Team
MITRE
Internal
updated Relationships, Other Notes,
Taxonomy Mappings
2009-05-27
CWE Content Team
MITRE
Internal
updated Description
2009-10-29
CWE Content Team
MITRE
Internal
updated Modes of Introduction, Observed Examples,
Other Notes, Relationship Notes