Umbra Wiki weakness weakness/CWE-628
Back to wiki

CWE-628 — Function Call with Incorrectly Specified Arguments

provenance: imported · CWE: CWE-628

CWE-628: Function Call with Incorrectly Specified Arguments

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Draft
Likelihood of exploit

Description

The product calls a function, procedure, or routine with arguments that are not correctly specified, leading to always-incorrect behavior and resultant weaknesses.

There are multiple ways in which this weakness can be introduced, including: the wrong variable or reference; an incorrect number of arguments; incorrect order of arguments; wrong type of arguments; or wrong value.

Common consequences

  • Other, Access Control: Quality Degradation, Gain Privileges or Assume Identity

Mitigations

Build and Compilation — Once found, these issues are easy to fix. Use code inspection tools and relevant compiler features to identify potential violations. Pay special attention to code that is not likely to be exercised heavily during QA.

Architecture and Design — Make sure your API's are stable before you use them in production code.

References

  • CWE page: https://cwe.mitre.org/data/definitions/628.html
  • CWE list: https://cwe.mitre.org/data/index.html