Umbra Wiki weakness weakness/CWE-325
Back to wiki

CWE-325 — Missing Cryptographic Step

provenance: imported · CWE: CWE-325

CWE-325: Missing Cryptographic Step

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Draft
Likelihood of exploit

Description

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

Common consequences

  • Access Control: Bypass Protection Mechanism
  • Confidentiality, Integrity: Read Application Data, Modify Application Data
  • Accountability, Non-Repudiation: Hide Activities

Mitigations

(none listed)

References

  • CWE page: https://cwe.mitre.org/data/definitions/325.html
  • CWE list: https://cwe.mitre.org/data/index.html