CWE-453

Insecure Default Variable Initialization

Medium

Description

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Potential Impact

How to Fix

System Configuration

Disable or change default settings when they can be used to abuse the system. Since those default settings are shipped with the product they are likely to be known by a potential attacker who is familiar with the product. For instance, default credentials should be changed or the associated accounts should be disabled.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-453 vulnerabilities in your codebase.

Get Security Assessment