Einführungsmodi
Architecture and Design
Documentation
Anwendbare Plattformen
Sprache
Class: Not Language-Specific (Undetermined)
Betriebssysteme
Class: Not OS-Specific (Undetermined)
Architekturen
Class: Not Architecture-Specific (Undetermined)
Technologien
Class: Not Technology-Specific (Undetermined)
Class: ICS/OT (Undetermined)
Häufige Konsequenzen
| Bereich |
Auswirkung |
Wahrscheinlichkeit |
| Other | Varies by Context, Hide Activities, Reduce Reliability, Quality Degradation, Reduce Maintainability
Note: Without a method of verification, one cannot be sure that everything only functions as expected. | |
Beobachtete Beispiele
| Referenzen |
Beschreibung |
| A wireless access point manual specifies that the only method of configuration is via web interface (CWE-1059), but there is an undisclosed telnet server that was activated by default (CWE-912). |
Mögliche Gegenmaßnahmen
Phases : Documentation // Architecture and Design
Ensure that design documentation is detailed enough to allow for post-manufacturing verification.
Hinweise zur Schwachstellen-Zuordnung
Begründung : This entry is primarily a quality issue with no direct security implications.
Kommentar : Look for weaknesses that are focused specifically on insecure behaviors that have more direct security implications.
Referenzen
REF-1248
Categories of Security Vulnerabilities in ICS
Securing Energy Infrastructure Executive Task Force (SEI ETF).
https://secureenergy.inl.gov/content/uploads/27/2024/12/SEI-ETF-NCSV-TPT-Categories-of-Security-Vulnerabilities-ICS-v1_03-09-22.pdf REF-1254
Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions Draft Guidance for Industry and Food and Drug Administration Staff (DRAFT GUIDANCE)
FDA.
https://www.fda.gov/media/119933/download
Einreichung
| Name |
Organisation |
Datum |
Veröffentlichungsdatum |
Version |
| CWE Content Team |
MITRE |
2018-07-02 +00:00 |
2019-01-03 +00:00 |
3.2 |
Änderungen
| Name |
Organisation |
Datum |
Kommentar |
| CWE Content Team |
MITRE |
2020-02-24 +00:00 |
updated Relationships |
| CWE Content Team |
MITRE |
2022-04-28 +00:00 |
updated Applicable_Platforms, Common_Consequences, Description, Name, Potential_Mitigations, References, Relationships, Time_of_Introduction |
| CWE Content Team |
MITRE |
2023-01-31 +00:00 |
updated Applicable_Platforms, Relationships |
| CWE Content Team |
MITRE |
2023-04-27 +00:00 |
updated Relationships, Taxonomy_Mappings |
| CWE Content Team |
MITRE |
2023-06-29 +00:00 |
updated Mapping_Notes, Taxonomy_Mappings |
| CWE Content Team |
MITRE |
2023-10-26 +00:00 |
updated Observed_Examples |
| CWE Content Team |
MITRE |
2024-02-29 +00:00 |
updated Mapping_Notes |
| CWE Content Team |
MITRE |
2025-09-09 +00:00 |
updated References |