Detalle CWE-1125

CWE-1125

Excessive Attack Surface
Incomplete
2019-01-03
00h00 +00:00
2025-12-11
00h00 +00:00
Notificaciones para un CWE
Manténgase informado sobre cualquier cambio en un CWE específico.
Gestionar notificaciones

Nombre: Excessive Attack Surface

The product has an attack surface whose quantitative measurement exceeds a desirable maximum.

Informaciones generales

Modos de introducción

Implementation
Architecture and Design

Plataformas aplicables

Lenguaje

Class: Not Language-Specific (Undetermined)

Consecuencias comunes

Alcance Impacto Probabilidad
OtherVaries by Context

Notas de mapeo de vulnerabilidades

Justificación : This entry is primarily a quality issue with no direct security implications.
Comentario : Look for weaknesses that are focused specifically on insecure behaviors that have more direct security implications.

Referencias

REF-966

An Attack Surface Metric
Pratyusa Manadhata.
http://reports-archive.adm.cs.cmu.edu/anon/2008/CMU-CS-08-152.pdf

REF-967

Measuring a System's Attack Surface
Pratyusa Manadhata, Jeannette M. Wing.
http://www.cs.cmu.edu/afs/cs/usr/wing/www/publications/ManadhataWing04.pdf

Envío

Nombre Organización Fecha Fecha de lanzamiento Version
CWE Content Team MITRE 2018-07-02 +00:00 2019-01-03 +00:00 3.2

Modificaciones

Nombre Organización Fecha Comentario
CWE Content Team MITRE 2020-02-24 +00:00 updated Relationships
CWE Content Team MITRE 2023-04-27 +00:00 updated Relationships
CWE Content Team MITRE 2023-06-29 +00:00 updated Mapping_Notes
CWE Content Team MITRE 2024-02-29 +00:00 updated Mapping_Notes
CWE Content Team MITRE 2025-12-11 +00:00 updated Applicable_Platforms, Common_Consequences, Relationships, Time_of_Introduction