CWE Database
/

CWE-453

Back to CWE list

CWE-453

Insecure Default Variable Initialization

Variant
Draft

Description

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Common Consequences

Scope

Integrity

Impact

Modify Application Data

Potential Mitigations

System Configuration

Disable or change default settings when they can be used to abuse the system. Since those default settings are shipped with the product they are likely to be known by a potential attacker who is familiar with the product. For instance, default credentials should be changed or the associated accounts should be disabled.

CVE-2022-36349

insecure default variable initialization in BIOS firmware for a hardware board allows DoS

Applicable Platforms

PHP
Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now