COMMON WEAKNESS ENUMERATIONIncomplete

CWE-1188

Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Soyutlama

Base

Yapı

Simple

Sömürü İhtimali

Medium

Problemi anla

Problem nedir?

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Kök neden

Problem nasıl ve ne zaman oluşur?

Yaşam döngüsü evresi

Implementation

Developers often choose default values that leave the product as open and easy to use as possible out-of-the-box, under the assumption that the administrator can (or should) change the default value. However, this ease-of-use comes at a cost when the default is insecure and the administrator does not change it.

Yaşam döngüsü evresi

System Configuration

Risk

Başarılı sömürü neye yol açar?

Varies by Context

Etkilenen güvenlik alanları: Other

The impact of insecure defaults varies widely depending on the functionality that the product controls.

Savunma

Nasıl önlenir ve çözülür?

  • Follow secure coding guidelines for input handling and boundary checking.
  • Enforce strict security reviews and automated static analysis (SAST) checks.

Doğrulama

Nasıl tespit edilir?

Automated Static Analysis

Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)