CWE-340
Generation of Predictable Numbers or Identifiers
Description
The product uses a scheme that generates numbers or identifiers that are more predictable than required.
Parent Weaknesses (ChildOf)
Related Weaknesses
Common Consequences
Scope
Impact
Varies by Context
CVE-2022-29330Product for administering PBX systems uses predictable identifiers and timestamps for filenames (CWE-340) which allows attackers to access files via direct request (CWE-425).
CVE-2001-1141PRNG allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predict future pseudo-random numbers.
CVE-1999-0074Listening TCP ports are sequentially allocated, allowing spoofing attacks.
Applicable Platforms
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now