The software, by default, initializes an internal variable with
an insecure or less secure value than is possible.
Time of Introduction
Architecture and Design
Implementation
Operation
Applicable Platforms
Languages
PHP: (Sometimes)
All
Potential Mitigations
Phase
Description
Disable or change default settings when they can be used to abuse the
system. Since those default settings are shipped with the product they
are likely to be known by a potential attacker who is familiar with the
product. For instance, default credentials should be changed or the
associated accounts should be disabled.
Other Notes
This overlaps other categories, probably should be split into separate
items.