VariantDraft
CWE-453Insecure Default Variable Initialization
Category: config
Description
The product, by default, initializes an internal variable with an insecure or less secure value than is possible.
Common consequences· 1
- Integrity — Modify Application DataAn attacker could gain access to and modify sensitive data or system information.
Potential mitigations· 1
- [System Configuration]Disable or change default settings when they can be used to abuse the system. Since those default settings are shipped with the product they are likely to be known by a potential attacker who is familiar with the product. For instance, default credentials should be changed or the associated accounts should be disabled.
References
(incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-30206cve-2025-30206 | 0% | live |
| Vulnerability | CVE-2025-47945cve-2025-47945 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.