Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. The Crypt::PK::RSA, Crypt::
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is in
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an objec
Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi
Frequently Asked Questions
What is CWE-335?
CWE-335 (CWE-335) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-335?
There are 5 CVE records associated with CWE-335 in our database. Of these, 0 are critical severity, 4 are high severity, and 1 are medium severity.
How can I protect against CWE-335 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-335 using AI-powered security agents.
Detect CWE-335 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-335 vulnerabilities across your infrastructure.
Get Started