BaseDraft
CWE-342Predictable Exact Value from Previous Values
Category: other
Description
An exact value or random number can be precisely predicted by observing previous values.
Common consequences· 1
- Other — Varies by Context
Potential mitigations· 3
- []Increase the entropy used to seed a PRNG.
- [Architecture and Design, Requirements]Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C ("Approved Random Number Generators").
- [Implementation]Use a PRNG that periodically re-seeds itself using input from high-quality sources, such as hardware devices with high entropy. However, do not re-seed too frequently, or else the entropy source might block.
References
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.