Umbra Wiki weakness weakness/CWE-326
Back to wiki

CWE-326 — Inadequate Encryption Strength

provenance: imported · CWE: CWE-326

CWE-326: Inadequate Encryption Strength

MITRE CWE weakness

Kind Weakness
Abstraction Class
Status Draft
Likelihood of exploit

Description

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.

Common consequences

  • Access Control, Confidentiality: Bypass Protection Mechanism, Read Application Data

Mitigations

Architecture and Design — Use an encryption scheme that is currently considered to be strong by experts in the field.

References

  • CWE page: https://cwe.mitre.org/data/definitions/326.html
  • CWE list: https://cwe.mitre.org/data/index.html