CWE-325 缺少必要的密码学步骤

admin 2022年1月7日02:22:01评论59 views字数 1412阅读4分42秒阅读模式

CWE-325 缺少必要的密码学步骤

Missing Required Cryptographic Step

结构: Simple

Abstraction: Base

状态: Incomplete

被利用可能性: unkown

基本描述

The software does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by that algorithm.

扩展描述

Cryptographic implementations should follow the algorithms that define them exactly, otherwise encryption can be weaker than expected.

相关缺陷

  • cwe_Nature: ChildOf cwe_CWE_ID: 573 cwe_View_ID: 1000 cwe_Ordinal: Primary

  • cwe_Nature: PeerOf cwe_CWE_ID: 358 cwe_View_ID: 1000

适用平台

Language: {'cwe_Class': 'Language-Independent', 'cwe_Prevalence': 'Undetermined'}

常见的影响

范围 影响 注释
Access Control Bypass Protection Mechanism If the cryptographic algorithm is used for authentication and authorization, then an attacker could gain unauthorized access to the system.
['Confidentiality', 'Integrity'] ['Read Application Data', 'Modify Application Data'] Sensitive data may be compromised by the use of a broken or risky cryptographic algorithm.
['Accountability', 'Non-Repudiation'] Hide Activities If the cryptographic algorithm is used to ensure the identity of the source of the data (such as digital signatures), then a broken algorithm will compromise this scheme and the source of the data cannot be proven.

分析过的案例

标识 说明 链接

Notes

Relationship
Overlaps incomplete/missing security check.
Relationship
Can be resultant.

分类映射

映射的分类名 ImNode ID Fit Mapped Node Name
PLOVER Missing Required Cryptographic Step
OWASP Top Ten 2007 A8 CWE More Specific Insecure Cryptographic Storage
OWASP Top Ten 2007 A9 CWE More Specific Insecure Communications

相关攻击模式

  • CAPEC-68

文章来源于互联网:scap中文网

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2022年1月7日02:22:01
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   CWE-325 缺少必要的密码学步骤http://cn-sec.com/archives/612774.html

发表评论

匿名网友 填写信息