CWE-330 — Use of Insufficiently Random Values
CWE-330: Use of Insufficiently Random Values
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Class |
| Status | Stable |
| Likelihood of exploit | High |
Description
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Common consequences
- Confidentiality, Other: Other
- Access Control, Other: Bypass Protection Mechanism, Other
- Access Control: Bypass Protection Mechanism, Gain Privileges or Assume Identity
Mitigations
Architecture and Design — Use a well-vetted algorithm that is currently considered to be strong by experts in the field, and select well-tested implementations with adequate length seeds. In general, if a pseudo-random number generator is not advertised as being cryptographically secure, then it is probably a statistical PRNG and should not be used in security-sensitive contexts. Pseudo-random number generators can produce predictable numbers if the generator is known and the seed can be guessed. A 256-bit seed is a good starting point for producing a "random enough" number.
Implementation — Consider a PRNG that re-seeds itself as needed from high quality pseudo-random output sources, such as hardware devices.
Architecture and Design — Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C ("Approved Random Number Generators").
References
- CWE page: https://cwe.mitre.org/data/definitions/330.html
- CWE list: https://cwe.mitre.org/data/index.html