CWE-470 là gì?
Đang phân tích dữ liệu...
Đang phân tích dữ liệu...
| Tác động | Phạm vi | Diễn giải |
|---|---|---|
| Thực thi mã hoặc lệnh trái phép, Thay đổi logic thực thi | Tính toàn vẹn, Tính bí mật, Tính sẵn sàng, Khác | The attacker might be able to execute code that is not directly accessible to the attacker. Alternately, the attacker could call unexpected code in the wrong place or the wrong time, possibly modifying critical system state. |
| Từ chối dịch vụ: sập, thoát hoặc khởi động lại, Khác | Tính sẵn sàng, Khác | The attacker might be able to use reflection to call the wrong code, possibly with unexpected arguments that violate the API (CWE-227). This could cause the product to exit or hang. |
| Đọc dữ liệu ứng dụng | Tính bí mật | By causing the wrong code to be invoked, the attacker might be able to trigger a runtime error that leaks sensitive information in the error message, such as CWE-536. |
| Phương pháp | Cách làm | Hiệu quả |
|---|---|---|
| Phân tích tĩnh tự động | Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.) | Cao |
Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-470, dựa theo mức độ ưu tiên
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.
Khám phá CyStack VulnScanvi