Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-358 (不恰当实现的标准安全检查) — Vulnerability Class 81

81 vulnerabilities classified as CWE-358 (不恰当实现的标准安全检查). AI Chinese analysis included.

CWE-358 represents a critical implementation flaw where developers fail to correctly execute security checks mandated by established standards, protocols, or algorithms. This weakness typically arises when engineers misunderstand complex specifications or attempt to optimize performance by skipping mandatory validation steps, resulting in a system that appears compliant but lacks actual security. Attackers exploit this gap by crafting inputs that bypass the incomplete checks, effectively neutralizing intended protections such as authentication mechanisms or data integrity verifications. To prevent CWE-358, developers must rigorously adhere to standardized guidelines, utilizing automated testing tools that verify compliance with specific protocol requirements. Comprehensive code reviews focusing on security-critical paths and staying updated with the latest standard revisions ensure that all mandated checks are implemented accurately, thereby closing the vulnerability window before deployment.

MITRE CWE Description
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
Common Consequences (1)
Access ControlBypass Protection Mechanism
CVE IDTitleCVSSSeverityPublished
CVE-2020-25686 Dnsmasq 安全特征问题漏洞 — dnsmasq 3.7 -2021-01-20
CVE-2020-25684 Dnsmasq 安全漏洞 — dnsmasq 3.7 -2021-01-20
CVE-2020-8352 Lenovo Desktop 安全特征问题漏洞 — BIOS 2.4 Low2020-11-11
CVE-2020-1728 Red Hat Keycloak 安全特征问题漏洞 — keycloak 4.8 Medium2020-04-06
CVE-2020-7251 ESConfig Tool able to edit configuration for newer version — Mcafee Endpoint Security (ENS) 5.0 Medium2020-02-14
CVE-2019-14823 JSS CryptoManager 安全特征问题漏洞 — JSS 7.4 -2019-10-14
CVE-2018-16860 Samba 安全漏洞 — samba 7.5 -2019-07-31
CVE-2019-6742 Samsung Galaxy S9 代码注入漏洞 — Galaxy S9 8.8 -2019-06-03
CVE-2019-3894 Red Hat Wildfly Elytron子系统权限许可和访问控制问题漏洞 — wildfly 8.8 -2019-05-03
CVE-2019-3806 PowerDNS Recursor 安全特征问题漏洞 — pdns-recursor 8.1 -2019-01-29
CVE-2018-16857 Samba 安全漏洞 — samba 6.5 -2018-11-28
CVE-2018-7685 libzypp does not reevaluate malicious rpms once downloaded — libzypp 9.8 -2018-08-31
CVE-2016-8635 Mozilla Network Security Services 信息泄露漏洞 — nss 5.9 -2018-08-01
CVE-2016-8614 Ansible 安全漏洞 — Ansible 5.9 -2018-07-31
CVE-2018-0268 Cisco Digital Network Architecture Center 安全漏洞 — Cisco Digital Network Architecture Center 10.0 -2018-05-17
CVE-2017-2604 CloudBees Jenkins 权限许可和访问控制漏洞 — jenkins 6.5 -2018-05-15
CVE-2017-2612 CloudBees Jenkins 安全漏洞 — jenkins 5.4 -2018-05-15
CVE-2017-2611 CloudBees Jenkins 安全漏洞 — jenkins 4.3 -2018-05-08
CVE-2017-15107 Dnsmasq 安全漏洞 — dnsmasq--2018-01-23
CVE-2017-15105 Unbound 安全漏洞 — unbound 5.3 -2018-01-23
CVE-2017-12303 Cisco Web Security Appliance Cisco AsyncOS Software 安全漏洞 — Cisco Web Security Appliance 5.3 -2017-11-16

Vulnerabilities classified as CWE-358 (不恰当实现的标准安全检查) represent 81 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.