CWE-334

Small Space of Random Values

High

Description

The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.

Potential Impact

How to Fix

Architecture and Design

Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C ("Approved Random Number Generators").

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-334 vulnerabilities in your codebase.

Get Security Assessment