CWE-23 là gì?
Đang phân tích dữ liệu...
Đang phân tích dữ liệu...
Dữ liệu thống kê hiện chưa khả dụng.
| Tác động | Phạm vi | Diễn giải |
|---|---|---|
| Thực thi mã hoặc lệnh trái phép | Tính toàn vẹn, Tính bí mật, Tính sẵn sàng | The attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries. |
| Thay đổi tệp hoặc thư mục | Tính toàn vẹn | The attacker may be able to overwrite or create critical files, such as programs, libraries, or important data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, appending a new account at the end of a password file may allow an attacker to bypass authentication. |
| Đọc tệp hoặc thư mục | Tính bí mật | The attacker may be able read the contents of unexpected files and expose sensitive data by traversing the file system to access files or directories that are outside of the restricted directory. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, by reading a password file, the attacker could conduct brute force password guessing attacks in order to break into an account on the system. |
| Từ chối dịch vụ: sập, thoát hoặc khởi động lại | Tính sẵn sàng | The attacker may be able to overwrite, delete, or corrupt unexpected critical files such as programs, libraries, or important data. This may prevent the product from working at all and in the case of a protection mechanisms such as authentication, it has the potential to lockout every user of the product. |
| Phương pháp | Cách làm | Hiệu quả |
|---|---|---|
| Phân tích tĩnh tự động | Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.) | Cao |
Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-23, dựa theo mức độ ưu tiên
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.
Khám phá CyStack VulnScanvi