CWE一覧に戻る
CWE-453

安全でないデフォルト変数の初期化

Insecure Default Variable Initialization
脆弱性 レビュー中
JA

製品はデフォルトで、内部変数を安全でない、あるいは可能な限り安全でない値で初期化する。

EN

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Scope: Integrity / Impact: Modify Application Data
Disable or change default settings when they can be used to abuse the system. Since those default settings are shipped with the product they are likely to be known by a potential attacker who is familiar with the product. For instance, default credentials should be changed or the associated accounts should be disabled.
MITRE公式ページ — CWE-453