CWE-1446: Category: Weaknesses That are Specific to AI/ML Technology

ClassIncomplete

This category identifies weaknesses that are uniquely applicable to AI/ML technology.

View on MITRE
Back to CWE Lookup

Extended Description

This entry is a Category. Using categories for mapping has been discouraged since 2019. Categories are informal organizational groupings of weaknesses that can help CWE users with data aggregation, navigation, and browsing. However, they are not weaknesses in themselves. CWE users might be tempted to use this CWE for mapping, but it is a category (see Reasons). Mappers should consider whether a weakness is unique to AI/ML (in which case a high-level Pillar or class might still apply), or if it is a general software weakness that happens to appear in AI/ML related software.

Technical Details

Structure
Simple
Vulnerability Mapping
PROHIBITED

Applicable To

Languages
Platforms

Source-backed guidance

Additional facts reviewed against primary or authoritative security sources.

Use CWE-1446 to navigate Weaknesses That are Specific to AI/ML Technology

MITRE defines CWE-1446 as an organizational category with 4 members, including CWE-1039, CWE-1426, CWE-1427, and CWE-1434. Use it for aggregation, navigation, and browsing; because a category is not itself a weakness, do not use it as the root-cause mapping for a vulnerability. Follow the member CWE entries for implementation and verification guidance.

CWE-1446: Weaknesses That are Specific to AI/ML TechnologyMITRE CWE

Frequently Asked Questions

What is CWE-1446: Category: Weaknesses That are Specific to AI/ML Technology?+

CWE-1446: Category: Weaknesses That are Specific to AI/ML Technology is a Common Weakness Enumeration (CWE) entry maintained by MITRE. This category identifies weaknesses that are uniquely applicable to AI/ML technology. This entry is a Category. Using categories for mapping has been discouraged since 2019. Categories are informal organizational groupings of weaknesses that can help CWE users with data aggregation, navigation, and browsing. However, they are not weaknesses in themselves. CWE users might be tempted to use this CWE for mapping, but it is a category (see Reasons). Mappers should consider whether a weakness is unique to AI/ML (in which case a high-level Pillar or class might still apply), or if it is a general software weakness that happens to appear in AI/ML related software.

What is the difference between a CWE and a CVE?+

A CWE (Common Weakness Enumeration) like CWE-1446 describes a category of software weakness — the underlying flaw type. A CVE (Common Vulnerabilities and Exposures) identifies a specific, real-world vulnerability in a particular product. In short, a CWE is the kind of mistake, and a CVE is an instance of that mistake being found in software.

Learn More

Advertisement