CWE-1125 Detail

CWE-1125

Excessive Attack Surface
Incomplete
2019-01-03 00:00 +00:00
2024-02-29 00:00 +00:00

Alerte pour un CWE

Stay informed of any changes for a specific CWE.
Alert management

Excessive Attack Surface

The product has an attack surface whose quantitative measurement exceeds a desirable maximum.

Extended Description

Originating from software security, an "attack surface" measure typically reflects the number of input points and output points that can be utilized by an untrusted party, i.e. a potential attacker. A larger attack surface provides more places to attack, and more opportunities for developers to introduce weaknesses. In some cases, this measure may reflect other aspects of quality besides security; e.g., a product with many inputs and outputs may require a large number of tests in order to improve code coverage.

Informations

Vulnerability Mapping Notes

Rationale : This entry is primarily a quality issue with no direct security implications.
Comments : Look for weaknesses that are focused specifically on insecure behaviors that have more direct security implications.

References

REF-966

An Attack Surface Metric
Pratyusa Manadhata.
http://reports-archive.adm.cs.cmu.edu/anon/2008/CMU-CS-08-152.pdf

REF-967

Measuring a System's Attack Surface
Pratyusa Manadhata, Jeannette M. Wing.
http://www.cs.cmu.edu/afs/cs/usr/wing/www/publications/ManadhataWing04.pdf

Submission

Name Organization Date Date Release Version
CWE Content Team MITRE 2018-07-02 +00:00 2019-01-03 +00:00 3.2

Modifications

Name Organization Date Comment
CWE Content Team MITRE 2020-02-24 +00:00 updated Relationships
CWE Content Team MITRE 2023-04-27 +00:00 updated Relationships
CWE Content Team MITRE 2023-06-29 +00:00 updated Mapping_Notes
CWE Content Team MITRE 2024-02-29 +00:00 updated Mapping_Notes
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.