Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-330 (使用不充分的随机数) — Vulnerability Class 126

126 vulnerabilities classified as CWE-330 (使用不充分的随机数). AI Chinese analysis included.

CWE-330 represents a critical weakness where software relies on predictable or insufficiently random values within security-sensitive contexts, such as session token generation or cryptographic key creation. Attackers typically exploit this flaw by analyzing patterns in the generated values to predict future outputs, thereby bypassing authentication mechanisms or hijacking active user sessions. This vulnerability often stems from the misuse of standard pseudo-random number generators that lack cryptographic security properties. To mitigate this risk, developers must employ cryptographically secure pseudo-random number generators (CSPRNGs) that are specifically designed to resist prediction even if previous outputs are known. Additionally, ensuring proper seeding with high-entropy sources and avoiding custom randomization algorithms are essential practices for maintaining the integrity of security-dependent operations.

MITRE CWE Description
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Common Consequences (3)
Confidentiality, Other Other
When a protection mechanism relies on random values to restrict access to a sensitive resource, such as a session ID or a seed for generating a cryptographic key, then the resource being protected could be accessed by guessing the ID or key.
Access Control, Other Bypass Protection Mechanism, Other
If product relies on unique, unguessable IDs to identify a resource, an attacker might be able to guess an ID for a resource that is owned by another user. The attacker could then read the resource, or pre-create a resource with the same ID to prevent the legitimate program from properly sending the…
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity
When an authorization or authentication mechanism relies on random values to restrict access to restricted functionality, such as a session ID or a seed for generating a cryptographic key, then an attacker may access the restricted functionality by guessing the ID or key.
Mitigations (3)
Architecture and Design Use a well-vetted algorithm that is currently considered to be strong by experts in the field, and select well-tested implementations with adequate length seeds. In general, if a pseudo-random number generator is not advertised as being cryptographically secure, then it is probably a statistical PRNG and should not be used in security-sensitive contexts. Pseudo-random number generators can produce…
Implementation Consider a PRNG that re-seeds itself as needed from high quality pseudo-random output sources, such as hardware devices.
Architecture and Design, Requirements Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C ("Approved Random Number Generators").
Examples (2)
This code attempts to generate a unique random identifier for a user's session.
function generateSessionID($userID){ srand($userID); return rand(); }
Bad · PHP
The following code uses a statistical PRNG to create a URL for a receipt that remains active for some period of time after a purchase.
String GenerateReceiptURL(String baseUrl) { Random ranGen = new Random(); ranGen.setSeed((new Date()).getTime()); return(baseUrl + ranGen.nextInt(400000000) + ".html"); }
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2024-21460 Use of Insufficiently Random Values in Core — Snapdragon 7.1 High 2024-07-01
CVE-2024-25943 Dell iDRAC9 安全漏洞 — Integrated Dell Remote Access Controller 9 7.6 High 2024-06-29
CVE-2024-5868 WooCommerce - Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness — WooCommerce - Social Login 6.5 Medium 2024-06-15
CVE-2024-35292 多款Siemens产品 安全特征问题漏洞 — SIMATIC S7-200 SMART CPU CR40 8.2 High 2024-06-11
CVE-2024-5149 BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness — Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) 6.5 Medium 2024-06-05
CVE-2024-36389 MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values — DeviceHub 9.8 Critical 2024-06-02
CVE-2024-4185 Customer Email Verification for WooCommerce <= 2.7.4 - Email Verification and Authentication Bypass due to Insufficient Randomness — Customer Email Verification for WooCommerce 8.1 High 2024-04-30
CVE-2023-6799 WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomness — WP Reset 5.9 Medium 2024-04-09
CVE-2024-28013 NEC Corporation Aterm 安全漏洞 — WG1800HP4 8.1AI High AI 2024-03-28
CVE-2024-21495 caddy-security 安全漏洞 — github.com/greenpau/caddy-security 6.5 Medium 2024-02-17
CVE-2024-0761 File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames — File Manager 8.1 High 2024-02-05
CVE-2023-46740 Insecure random string generator used for sensitive data — cubefs 6.5 Medium 2024-01-03
CVE-2023-4462 Poly VVX 601 Web Configuration Application random values — Trio 8300 3.7 Low 2023-12-29
CVE-2023-6376 Henschen & Associates court document management software cache uses predictable file names — court document management software 5.3 Medium 2023-11-30
CVE-2023-29332 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability — Azure Kubernetes Service 7.5 High 2023-09-12
CVE-2023-41879 Magento LTS's guest order "protect code" can be brute-forced too easily — magento-lts 7.5 High 2023-09-11
CVE-2023-34353 Open Automation Software OAS Platform 安全特征问题漏洞 — OAS Platform 7.5 High 2023-09-05
CVE-2023-26451 Open-Xchange AppSuite 安全特征问题漏洞 — OX App Suite 7.5 High 2023-08-02
CVE-2023-3803 Chengdu Flash Flood Disaster Monitoring and Warning System File Name ImageStationDataService.asmx random values — Flash Flood Disaster Monitoring and Warning System 2.6 Low 2023-07-21
CVE-2023-20185 Cisco Nexus 9000 Series Fabric Switches 加密问题漏洞 — Cisco NX-OS System Software in ACI Mode 7.4 High 2023-07-12
CVE-2022-43485 Insecure random number used for generating keys for signing Jwt tokens — OneWireless 6.2 Medium 2023-05-30
CVE-2023-31147 Insufficient randomness in generation of DNS query IDs in c-ares — c-ares 5.9 Medium 2023-05-25
CVE-2023-31124 AutoTools does not set CARES_RANDOM_FILE during cross compilation — c-ares 3.7 Low 2023-05-25
CVE-2023-1385 Amazon Fire TV Stick 安全特征问题漏洞 — Fire TV Stick 3rd gen 7.1 High 2023-05-03
CVE-2023-2418 Konga Login API random values — Konga 3.1 Low 2023-04-29
CVE-2023-30797 Insecure Random Generation in Netflix Lemur — Lemur 7.5 High 2023-04-19
CVE-2022-43636 TP-LINK TL-WR940N 安全特征问题漏洞 — TL-WR940N 8.8 - 2023-03-29
CVE-2022-26080 Easily guessable session ID's in NE843 Pulsar Plus Controller — Pulsar Plus System Controller NE843_S 6.3 Medium 2023-03-16
CVE-2022-39216 Combodo iTop's weak password reset token leads to account takeover — iTop 7.4 High 2023-03-14
CVE-2022-43501 KASAGO IPv6/v4 Dual 安全特征问题漏洞 — Kasago IPv6/v4 Dual 8.2 - 2023-02-10

Vulnerabilities classified as CWE-330 (使用不充分的随机数) represent 126 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.