CWE-1125 Details

CWE-1125

Excessive Attack Surface
Incomplete
2019-01-03
00h00 +00:00
2025-12-11
00h00 +00:00
Benachrichtigungen für ein CWE
Bleiben Sie über alle Änderungen zu einem bestimmten CWE informiert.
Benachrichtigungen verwalten

Name: Excessive Attack Surface

The product has an attack surface whose quantitative measurement exceeds a desirable maximum.

Allgemeine Informationen

Einführungsmodi

Implementation
Architecture and Design

Anwendbare Plattformen

Sprache

Class: Not Language-Specific (Undetermined)

Häufige Konsequenzen

Bereich Auswirkung Wahrscheinlichkeit
OtherVaries by Context

Hinweise zur Schwachstellen-Zuordnung

Begründung : This entry is primarily a quality issue with no direct security implications.
Kommentar : Look for weaknesses that are focused specifically on insecure behaviors that have more direct security implications.

Referenzen

REF-966

An Attack Surface Metric
Pratyusa Manadhata.
http://reports-archive.adm.cs.cmu.edu/anon/2008/CMU-CS-08-152.pdf

REF-967

Measuring a System's Attack Surface
Pratyusa Manadhata, Jeannette M. Wing.
http://www.cs.cmu.edu/afs/cs/usr/wing/www/publications/ManadhataWing04.pdf

Einreichung

Name Organisation Datum Veröffentlichungsdatum Version
CWE Content Team MITRE 2018-07-02 +00:00 2019-01-03 +00:00 3.2

Änderungen

Name Organisation Datum Kommentar
CWE Content Team MITRE 2020-02-24 +00:00 updated Relationships
CWE Content Team MITRE 2023-04-27 +00:00 updated Relationships
CWE Content Team MITRE 2023-06-29 +00:00 updated Mapping_Notes
CWE Content Team MITRE 2024-02-29 +00:00 updated Mapping_Notes
CWE Content Team MITRE 2025-12-11 +00:00 updated Applicable_Platforms, Common_Consequences, Relationships, Time_of_Introduction