目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-330 使用不充分的随机数 类漏洞列表 141

CWE-330 使用不充分的随机数 类弱点 141 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-330属于密码学相关漏洞,指在依赖不可预测数值的安全场景中使用了随机性不足的数值。攻击者通常通过分析伪随机数生成器的弱点,预测或重现关键值,从而绕过身份验证或会话管理。开发者应避免使用标准库中的伪随机函数处理敏感数据,转而采用操作系统提供的加密安全随机数生成器,并确保种子来源具备足够的熵,以保障数值不可预测性。

MITRE CWE 官方描述
CWE:CWE-330 使用不足够随机的值 (Use of Insufficiently Random Values) 英文:产品在一个依赖于不可预测数字的安全上下文中使用了不足够随机的数字或值。
常见影响 (3)
Confidentiality, Other Other
When a protection mechanism relies on random values to restrict access to a sensitive resource, such as a session ID or a seed for generating a cryptographic key, then the resource being protected could be accessed by guessing the ID or key.
Access Control, Other Bypass Protection Mechanism, Other
If product relies on unique, unguessable IDs to identify a resource, an attacker might be able to guess an ID for a resource that is owned by another user. The attacker could then read the resource, or pre-create a resource with the same ID to prevent the legitimate program from properly sending the…
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity
When an authorization or authentication mechanism relies on random values to restrict access to restricted functionality, such as a session ID or a seed for generating a cryptographic key, then an attacker may access the restricted functionality by guessing the ID or key.
缓解措施 (3)
Architecture and Design Use a well-vetted algorithm that is currently considered to be strong by experts in the field, and select well-tested implementations with adequate length seeds. In general, if a pseudo-random number generator is not advertised as being cryptographically secure, then it is probably a statistical PRNG and should not be used in security-sensitive contexts. Pseudo-random number generators can produce…
Implementation Consider a PRNG that re-seeds itself as needed from high quality pseudo-random output sources, such as hardware devices.
Architecture and Design, Requirements Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C ("Approved Random Number Generators").
代码示例 (2)
This code attempts to generate a unique random identifier for a user's session.
function generateSessionID($userID){ srand($userID); return rand(); }
Bad · PHP
The following code uses a statistical PRNG to create a URL for a receipt that remains active for some period of time after a purchase.
String GenerateReceiptURL(String baseUrl) { Random ranGen = new Random(); ranGen.setSeed((new Date()).getTime()); return(baseUrl + ranGen.nextInt(400000000) + ".html"); }
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-76105 Dell Container Storage Modules 1.18.0前使用随机数不足漏洞 — Container Storage Modules 7.7 High 2026-10-06
CVE-2026-102719 NetX Secure DTLS Cookie可预测漏洞 — netxduo 6.3 Medium 2026-09-29
CVE-2026-96599 Isotope eCommerce 2.9.10 弱订单标识符生成漏洞 — isotope-core 5.9 Medium 2026-09-23
CVE-2026-92930 OpenEye Apex NVR 3.2.9.376 管理员密码重置缺陷 — Apex Network Video Recorder (NVR) 6.2 Medium 2026-09-22
CVE-2026-80154 Lantronix设备会话令牌验证绕过漏洞 — SLC8000 9.6 Critical 2026-09-22
CVE-2026-92913 AVideo 弱随机数认证绕过漏洞 — AVideo 7.4 High 2026-09-17
CVE-2026-92912 AVideo 唯一ID密钥使用弱随机数生成器漏洞 — AVideo 6.5 Medium 2026-09-17
CVE-2026-19407 Gemini Enterprise Agent 平台 GCS Bucket 抢注致 RCE — Gemini Enterprise Agent Platform SDK for Python 7.7 High 2026-09-15
CVE-2026-86187 WWBN AVideo 加密问题漏洞 — AVideo 5.9 Medium 2026-09-05
CVE-2026-17274 IBM i 加密问题漏洞 — i 5.4 Medium 2026-09-04
CVE-2026-3416 WSO2 API Manager 加密问题漏洞 — WSO2 API Manager 5.9 Medium 2026-09-03
CVE-2026-81852 Ash Framework AshAdmin 加密问题漏洞 — ash_admin 2.1 Low 2026-08-31
CVE-2026-82555 TOTOLINK N600R 加密问题漏洞 — N600R 3.7 Low 2026-08-30
CVE-2026-19485 Google Vertex AI Search for Commerce 加密问题漏洞 — Vertex AI Search for Commerce 9.3 Critical 2026-08-26
CVE-2026-56706 Jakub Vrána Adminer 加密问题漏洞 — adminer 6.8 Medium 2026-08-25
CVE-2026-19896 Man D-Tale 加密问题漏洞 — dtale 3.7 Low 2026-08-15
CVE-2026-18531 IBM Maximo Application Suite 加密问题漏洞 — Maximo Application Suite 5.3 Medium 2026-08-05
CVE-2026-71225 chronox.de libkcapi 加密问题漏洞 — libkcapi 6.5 Medium 2026-08-05
CVE-2026-66391 Apache Wicket 泄露和缺少CSP头漏洞 — Apache Wicket - - 2026-07-27
CVE-2026-46351 BigBlueButton 加密问题漏洞 — bigbluebutton 8.1 High 2026-07-16
CVE-2026-47703 AdguardTeam AdGuardHome 加密问题漏洞 — AdGuardHome - - 2026-07-15
CVE-2026-14702 zcaceres markdownify-mcp 加密问题漏洞 — markdownify-mcp 2.5 Low 2026-07-05
CVE-2026-14570 TIMLEGGE Crypt::DSA 加密问题漏洞 — Crypt::DSA - - 2026-07-05
CVE-2026-45673 Netty 加密问题漏洞 — netty 6.8 Medium 2026-06-12
CVE-2026-41701 VMware Spring AMQP 安全特征问题漏洞 — Spring AMQP 4.4 Medium 2026-06-09
CVE-2026-41838 VMware Spring Framework 安全特征问题漏洞 — Spring Framework 4.8 Medium 2026-06-09
CVE-2026-41207 netty-incubator-codec-ohttp 安全特征问题漏洞 — netty-incubator-codec-ohttp - - 2026-06-04
CVE-2026-50208 Acer M6E 安全漏洞 — Connect M6E 5G Portable WiFi Router - - 2026-06-04
CVE-2026-44054 Netatalk 安全特征问题漏洞 — Netatalk 6.5 Medium 2026-05-21
CVE-2026-42155 magento-lts 安全特征问题漏洞 — magento-lts - - 2026-05-15

CWE-330(使用不充分的随机数) 是常见的弱点类别,本平台收录该类弱点关联的 141 条 CVE 漏洞。