目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-655 不充分的心理学可接受性 类漏洞列表 1

CWE-655 不充分的心理学可接受性 类弱点 1 条 CVE 漏洞汇总,含 AI 中文分析。

MITRE CWE 官方描述
The product has a protection mechanism that is too difficult or inconvenient to use, encouraging non-malicious users to disable or bypass the mechanism, whether by accident or on purpose.
常见影响 (1)
Access Control Bypass Protection Mechanism
By bypassing the security mechanism, a user might leave the system in a less secure state than intended by the administrator, making it more susceptible to compromise.
缓解措施 (2)
Testing Where possible, perform human factors and usability studies to identify where your product's security mechanisms are difficult to use, and why.
Architecture and Design Make the security mechanism as seamless as possible, while also providing the user with sufficient details when a security decision produces unexpected results.
代码示例 (2)
In "Usability of Security: A Case Study" [REF-540], the authors consider human factors in a cryptography product. Some of the weakness relevant discoveries of this case study were: users accidentally leaked sensitive information, could not figure out how to perform some tasks, thought they were enabling a security option when they were not, and made improper trust decisions.
Enforcing complex and difficult-to-remember passwords that need to be frequently changed for access to trivial resources, e.g., to use a black-and-white printer. Complex password requirements can also cause users to store the passwords in an unsafe manner so they don't have to remember them, such as using a sticky note or saving them in an unencrypted file.
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-33604 Open-Xchange Dovecot Pro 安全漏洞 — OX Dovecot Pro 5.9 Medium 2026-08-28

CWE-655(不充分的心理学可接受性) 是常见的弱点类别,本平台收录该类弱点关联的 1 条 CVE 漏洞。