CWE-453 — Insecure Default Variable Initialization
CWE-453: Insecure Default Variable Initialization
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Variant |
| Status | Draft |
| Likelihood of exploit | — |
Description
The product, by default, initializes an internal variable with an insecure or less secure value than is possible.
Common consequences
- Integrity: Modify Application Data
Mitigations
System Configuration — Disable or change default settings when they can be used to abuse the system. Since those default settings are shipped with the product they are likely to be known by a potential attacker who is familiar with the product. For instance, default credentials should be changed or the associated accounts should be disabled.
References
- CWE page: https://cwe.mitre.org/data/definitions/453.html
- CWE list: https://cwe.mitre.org/data/index.html
See all 1,245 pages under Weakness classes (CWE) →
Related pages
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.