Détail du CWE-1125

CWE-1125

Excessive Attack Surface
Incomplete
2019-01-03
00h00 +00:00
2024-02-29
00h00 +00:00
Notifications pour un CWE
Restez informé de toutes modifications pour un CWE spécifique.
Gestion des notifications

Nom: Excessive Attack Surface

The product has an attack surface whose quantitative measurement exceeds a desirable maximum.

Description du CWE

Originating from software security, an "attack surface" measure typically reflects the number of input points and output points that can be utilized by an untrusted party, i.e. a potential attacker. A larger attack surface provides more places to attack, and more opportunities for developers to introduce weaknesses. In some cases, this measure may reflect other aspects of quality besides security; e.g., a product with many inputs and outputs may require a large number of tests in order to improve code coverage.

Informations générales

Notes de cartographie des vulnérabilités

Justification : This entry is primarily a quality issue with no direct security implications.
Commentaire : Look for weaknesses that are focused specifically on insecure behaviors that have more direct security implications.

Références

REF-966

An Attack Surface Metric
Pratyusa Manadhata.
http://reports-archive.adm.cs.cmu.edu/anon/2008/CMU-CS-08-152.pdf

REF-967

Measuring a System's Attack Surface
Pratyusa Manadhata, Jeannette M. Wing.
http://www.cs.cmu.edu/afs/cs/usr/wing/www/publications/ManadhataWing04.pdf

Soumission

Nom Organisation Date Date de publication Version
CWE Content Team MITRE 2018-07-02 +00:00 2019-01-03 +00:00 3.2

Modifications

Nom Organisation Date Commentaire
CWE Content Team MITRE 2020-02-24 +00:00 updated Relationships
CWE Content Team MITRE 2023-04-27 +00:00 updated Relationships
CWE Content Team MITRE 2023-06-29 +00:00 updated Mapping_Notes
CWE Content Team MITRE 2024-02-29 +00:00 updated Mapping_Notes