Umbra Wiki weakness weakness/CWE-332
Back to wiki

CWE-332 — Insufficient Entropy in PRNG

provenance: imported · CWE: CWE-332

CWE-332: Insufficient Entropy in PRNG

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Draft
Likelihood of exploit Medium

Description

The lack of entropy available for, or used by, a Pseudo-Random Number Generator (PRNG) can be a stability and security threat.

Common consequences

  • Availability: DoS: Crash, Exit, or Restart
  • Access Control, Other: Bypass Protection Mechanism, Other

Mitigations

Architecture and Design — Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C ("Approved Random Number Generators").

Implementation — Consider a PRNG that re-seeds itself as needed from high-quality pseudo-random output, such as hardware devices.

Architecture and Design — When deciding which PRNG to use, look at its sources of entropy. Depending on what your security needs are, you may need to use a random number generator that always uses strong random data -- i.e., a random number generator that attempts to be strong but will fail in a weak way or will always provide some middle ground of protection through techniques like re-seeding. Generally, something that always provides a predictable amount of strength is preferable.

References

  • CWE page: https://cwe.mitre.org/data/definitions/332.html
  • CWE list: https://cwe.mitre.org/data/index.html