CWE-331

Insufficient Entropy
AI Translation Available

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Status
draft
Abstraction
base

Common Consequences

access control other
Impacts
bypass protection mechanism other

Detection Methods

automated static analysis

Potential Mitigations

Phases:
implementation
Descriptions:
• Determine the necessary entropy to adequately provide for randomness and predictability. This can be achieved by increasing the number of bits of objects such as keys and seeds.