| CWE |
CWE:326 |
Inadequate Encryption Strength |
| |
CWE:327 |
Use of a Broken or Risky Cryptographic Algorithm |
| |
CWE:330 |
Use of Insufficiently Random Values |
| |
CWE:338 |
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
| |
CWE:676 |
Use of Potentially Dangerous Function |
| CERT-C |
CERT-C:MSC25-C |
Do not use insecure or weak cryptographic algorithms |
| DISA-6r1 |
DISA-6r1:V-222397 |
The application must implement cryptographic mechanisms to protect the integrity of remote access sessions. |
| |
DISA-6r1:V-222570 |
The application must utilize FIPS-validated cryptographic modules when signing application components. |
| |
DISA-6r1:V-222571 |
The application must utilize FIPS-validated cryptographic modules when generating cryptographic hashes. |
| |
DISA-6r1:V-222572 |
The application must utilize FIPS-validated cryptographic modules when protecting unclassified information that requires cryptographic protection. |
| |
DISA-6r1:V-222583 |
The application must use the Federal Information Processing Standard (FIPS) 140-2-validated cryptographic modules and random number generator if the application implements encryption, key exchange, digital signature, and hash functionality. |
| |
DISA-6r1:V-222589 |
The application must use appropriate cryptography in order to protect stored DoD information when required by the information owner or DoD policy. |
| DISA-5r3 |
DISA-5r3:V-69259 |
The application must implement cryptographic mechanisms to protect the integrity of remote access sessions. |
| |
DISA-5r3:V-70191 |
The application must utilize FIPS-validated cryptographic modules when signing application components. |
| |
DISA-5r3:V-70193 |
The application must utilize FIPS-validated cryptographic modules when generating cryptographic hashes. |
| |
DISA-5r3:V-70195 |
The application must utilize FIPS-validated cryptographic modules when protecting unclassified information that requires cryptographic protection. |
| |
DISA-5r3:V-70217 |
The application must use the Federal Information Processing Standard (FIPS) 140-2-validated cryptographic modules and random number generator if the application implements encryption, key exchange, digital signature, and hash functionality. |
| |
DISA-5r3:V-70229 |
The application must use appropriate cryptography in order to protect stored DoD information when required by the information owner or DoD policy. |
| DISA-4r3 |
DISA-4r3:V-69259 |
The application must implement cryptographic mechanisms to protect the integrity of remote access sessions. |
| |
DISA-4r3:V-70191 |
The application must utilize FIPS-validated cryptographic modules when signing application components. |
| |
DISA-4r3:V-70193 |
The application must utilize FIPS-validated cryptographic modules when generating cryptographic hashes. |
| |
DISA-4r3:V-70195 |
The application must utilize FIPS-validated cryptographic modules when protecting unclassified information that requires cryptographic protection. |
| |
DISA-4r3:V-70217 |
The application must use the Federal Information Processing Standard (FIPS) 140-2-validated cryptographic modules and random number generator if the application implements encryption, key exchange, digital signature, and hash functionality. |
| |
DISA-4r3:V-70229 |
The application must use appropriate cryptography in order to protect stored DoD information when required by the information owner or DoD policy. |
| OWASP-2017 |
OWASP-2017:A2 |
Broken authentication |
| |
OWASP-2017:A3 |
Sensitive data exposure |
| |
OWASP-2017:A5 |
Broken access control |
| |
OWASP-2017:A9 |
Using components with known vulnerabilities |
| OWASP-2021 |
OWASP-2021:A1 |
Broken access control |
| |
OWASP-2021:A2 |
Cryptographic failures |
| |
OWASP-2021:A4 |
Insecure design |
| |
OWASP-2021:A6 |
Vulnerable and outdated components |
| |
OWASP-2021:A7 |
Identification and authorization failures |
| OWASP-2025 |
OWASP-2025:A01 |
Broken Access Control |
| |
OWASP-2025:A03 |
Software Supply Chain Failures |
| |
OWASP-2025:A04 |
Cryptographic Failures |
| |
OWASP-2025:A06 |
Insecure Design |