CWE-330
Overview
- CWE ID
- 330
- CWE Name
- Use of Insufficiently Random Values
- CWE Abstraction
- Class
- CWE structure
- Simple
- CWE Status
- Stable
Description
The software uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Extended Description
When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information.