CWE-757

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

High

Description

A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.

Potential Impact

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-757 vulnerabilities in your codebase.

Get Security Assessment