CWE-337: Predictable Seed in Pseudo-Random Number Generator (PRNG)

VariantDraft

A Pseudo-Random Number Generator (PRNG) is initialized from a predictable seed, such as the process ID or system time.

View on MITRE
Back to CWE Lookup

Extended Description

The use of predictable seeds significantly reduces the number of possible seeds that an attacker would need to test in order to predict which random numbers will be generated by the PRNG.

Technical Details

Structure
Simple

Applicable To

Languages
Not Language-Specific
Platforms

Learn More