CWE-325

Missing Cryptographic Step
AI Translation Available

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

Status
draft
Abstraction
base

Common Consequences

access control confidentiality integrity accountability non-repudiation
Impacts
bypass protection mechanism read application data modify application data hide activities

Detection Methods

automated static analysis

Potential Mitigations

Functional Areas

cryptography