CWE-1188: Initialization of a Resource with an Insecure Default

CWE-1188 là gì?

MITRE CWE

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Xác minh để phân tích mục CWE này

Bước xác minh ngắn giúp bảo vệ nguồn dữ liệu chính thức và hạn chế việc gọi AI tự động.

Mô tả chi tiết

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Đặc điểm

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Tác động thường gặp

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Biện pháp giảm thiểu

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Phương pháp phát hiện

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Lỗ hổng điển hình

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.
Dữ liệu MITRE CWE chính thứcMITRE CWE

Các trường dữ liệu và bằng chứng gốc từ hồ sơ MITRE CWE.

Nội dung gốc của MITRE được hiển thị bằng tiếng Anh khi nguồn không có bản địa hóa.

Định nghĩa MITRE gốc (tiếng Anh)

MITRE CWE

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Giai đoạn hình thành

  • Hiện thực hóa: Developers often choose default values that leave the product as open and easy to use as possible out-of-the-box, under the assumption that the administrator can (or should) change the default value. However, this ease-of-use comes at a cost when the default is insecure and the administrator does not change it.
  • Cấu hình hệ thống

Tác động thường gặp

  • Khác

    Thay đổi tùy ngữ cảnh

    The impact of insecure defaults varies widely depending on the functionality that the product controls.

Phương pháp phát hiện

  • Phân tích tĩnh tự độngAutomated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Lỗ hổng điển hình

Các ví dụ này chỉ minh họa cho mục CWE, không phải danh sách đầy đủ mọi lỗ hổng liên quan.

  • CVE-2022-36349insecure default variable initialization in BIOS firmware for a hardware board allows DoS
  • CVE-2022-42467A generic database browser interface has a default mode that exposes a web server to the network, allowing queries to the database.

Nguồn và tài liệu tham khảo

Tham chiếu

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan
CyStack VulnScan dashboard