Detect Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) with Automated Static Analysis
Documented detection approaches include Automated Static Analysis; recorded impacts include Bypass Protection Mechanism, and Other; observed examples include CVE-2020-7010, CVE-2019-11495, and CVE-2018-12520. Use these source-defined anchors to turn CWE-335 into implementation, review, and verification checks for the affected component.
CWE-335: Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) — MITRE CWE