CWE-640

CWE-640 là gì?

Đang phân tích dữ liệu...

Thống kê dữ liệu

THỨ HẠNG OWASP TOP 10:20257 — A07:2025 — Authentication Failures
TỔNG SỐ CVE LIÊN QUAN (365 NGÀY)52
MỨC TRỪU TƯỢNGCơ bản
KHẢ NĂNG KHAI THÁCCao

Số lượng lỗ hổng nằm trong CWE-640

52 lỗ hổngTăng 642,9% so với cùng kỳ

Số lượng lỗ hổng trong CISA KEV của CWE-640

0 lỗ hổng

Định nghĩa chính thức

TheoMitre CWE

Đặc điểm

Dữ liệu MITRE CWE chính thức

Giai đoạn hình thành

  • Kiến trúc và thiết kế: COMMISSION: This weakness refers to an incorrect design related to an architectural security tactic.
  • Hiện thực hóa

Hậu quả thường gặp

Dữ liệu MITRE CWE chính thức
Tác độngPhạm viDiễn giải
Chiếm đặc quyền hoặc mạo danhKiểm soát truy cậpAn attacker could gain unauthorized access to the system by retrieving legitimate user's authentication credentials.
Từ chối dịch vụ: tiêu thụ tài nguyên khácTính sẵn sàngAn attacker could deny service to legitimate system users by launching a brute force attack on the password recovery mechanism using user ids of legitimate users.
KhácTính toàn vẹn, KhácThe system's security functionality is turned against the system by the attacker.

Biện pháp giảm thiểu rủi ro

Dữ liệu MITRE CWE chính thức
  1. Kiến trúc và thiết kếMake sure that all input supplied by the user to the password recovery mechanism is thoroughly filtered and validated.
  2. Kiến trúc và thiết kếDo not use standard weak security questions and use several security questions.
  3. Kiến trúc và thiết kếMake sure that there is throttling on the number of incorrect answers to a security question. Disable the password recovery functionality after a certain (small) number of incorrect guesses.
  4. Kiến trúc và thiết kếRequire that the user properly answers the security question prior to resetting their password and sending the new password to the e-mail address of record.
  5. Kiến trúc và thiết kếNever allow the user to control what e-mail address the new password will be sent to in the password recovery mechanism.
  6. Kiến trúc và thiết kếAssign a new temporary password rather than revealing the original password.

Lỗ hổng điển hình

Nguồn (2)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan