|
Category ID: 1439
Vulnerability Mapping:
PROHIBITED
This CWE ID must not be used to map to real-world vulnerabilities
|
| Nature | Type | ID | Name |
|---|---|---|---|
| MemberOf | 1450 | Weaknesses in OWASP Top Ten RC1 (2025) | |
| HasMember | 261 | Weak Encoding for Password | |
| HasMember | 296 | Improper Following of a Certificate's Chain of Trust | |
| HasMember | 319 | Cleartext Transmission of Sensitive Information | |
| HasMember | 320 | Key Management Errors | |
| HasMember | 321 | Use of Hard-coded Cryptographic Key | |
| HasMember | 322 | Key Exchange without Entity Authentication | |
| HasMember | 323 | Reusing a Nonce, Key Pair in Encryption | |
| HasMember | 324 | Use of a Key Past its Expiration Date | |
| HasMember | 325 | Missing Cryptographic Step | |
| HasMember | 326 | Inadequate Encryption Strength | |
| HasMember | 327 | Use of a Broken or Risky Cryptographic Algorithm | |
| HasMember | 328 | Use of Weak Hash | |
| HasMember | 329 | Generation of Predictable IV with CBC Mode | |
| HasMember | 330 | Use of Insufficiently Random Values | |
| HasMember | 331 | Insufficient Entropy | |
| HasMember | 332 | Insufficient Entropy in PRNG | |
| HasMember | 334 | Small Space of Random Values | |
| HasMember | 335 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) | |
| HasMember | 336 | Same Seed in Pseudo-Random Number Generator (PRNG) | |
| HasMember | 337 | Predictable Seed in Pseudo-Random Number Generator (PRNG) | |
| HasMember | 338 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) | |
| HasMember | 340 | Generation of Predictable Numbers or Identifiers | |
| HasMember | 342 | Predictable Exact Value from Previous Values | |
| HasMember | 347 | Improper Verification of Cryptographic Signature | |
| HasMember | 523 | Unprotected Transport of Credentials | |
| HasMember | 757 | Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') | |
| HasMember | 759 | Use of a One-Way Hash without a Salt | |
| HasMember | 760 | Use of a One-Way Hash with a Predictable Salt | |
| HasMember | 780 | Use of RSA Algorithm without OAEP | |
| HasMember | 916 | Use of Password Hash With Insufficient Computational Effort | |
| HasMember | 1240 | Use of a Cryptographic Primitive with a Risky Implementation | |
| HasMember | 1241 | Use of Predictable Algorithm in Random Number Generator |
|
Usage: PROHIBITED
(this CWE ID must not be used to map to real-world vulnerabilities)
|
|
Reason: Category |
|
Rationale: This entry is a Category. Using categories for mapping has been discouraged since 2019. Categories are informal organizational groupings of weaknesses that can help CWE users with data aggregation, navigation, and browsing. However, they are not weaknesses in themselves. |
|
Comments: See member weaknesses of this category. |
Maintenance
|
[REF-1500] "OWASP Top 10:2025 RC1". OWASP. 2025-11-06.
<https://owasp.org/Top10/2025/0x00_2025-Introduction/>.
URL validated: 2025-12-01.
|
|
[REF-1504] OWASP. "A04:2025 - Cryptographic Failures". 2025-11-06.
<https://owasp.org/Top10/2025/A04_2025-Cryptographic_Failures/>.
URL validated: 2025-12-01.
|
|
Use of the Common Weakness Enumeration (CWE™) and the associated references from this website are subject to the Terms of Use. CWE is sponsored by the U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and managed by the Homeland Security Systems Engineering and Development Institute (HSSEDI) which is operated by The MITRE Corporation (MITRE). Copyright © 2006–2026, The MITRE Corporation. CWE, CWSS, CWRAF, and the CWE logo are trademarks of The MITRE Corporation. |
||

