CWE · MITRE source
CWE-331Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Last updated: 11 August 2026 10:53 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 5 mapping(s) from 4 framework(s): STIG oracle linux 8 2 (mostly) · STIG rhel 7 1 (mostly) · STIG rhel 8 1 (mostly) · CAPEC 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A04:2025 Cryptographic Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
Prevent
Stop it (NIST 800-53 / CSF Protect)
SC-12Cryptographic Key Establishment and ManagementPR.DS-01PR.DS-02PR.PS-06
Detect
Catch it (CSF Detect / Respond)
—
Harden
Shrink the surface (DISA STIG)
- 6 hardening rules · 3 OS baselines
Validate
Prove the fix (OWASP ASVS)
V6.5.2V11.3.4
NIST 800-53 r5 controls that address this weakness (1)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-12 | Cryptographic Key Establishment and Management | SC | Approved key-establishment methods mandate sufficient entropy during key generation, eliminating entropy-starved keys. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2018-18326 UPD | 8.0 | 7.5 | 0.5362 | 2019-07-03 |
CVE-2008-2108 UPD | 7.9 | 9.8 | 0.0429 | 2008-05-07 |
CVE-2018-15812 UPD | 7.8 | 7.5 | 0.4655 | 2019-07-03 |
CVE-2013-2260 UPD | 7.7 | 9.8 | 0.0216 | 2019-11-04 |
CVE-2008-1447 UPD | 7.6 | 6.8 | 0.9518 | 2008-07-08 |
CVE-2018-1000620 UPD | 7.6 | 9.8 | 0.0168 | 2018-07-09 |
CVE-2020-12735 UPD | 7.6 | 9.8 | 0.0172 | 2020-05-08 |
CVE-2020-10285 UPD | 7.6 | 9.8 | 0.0132 | 2020-07-15 |
CVE-2021-33027 UPD | 7.6 | 9.8 | 0.0132 | 2021-07-19 |
CVE-2021-22727 UPD | 7.6 | 9.8 | 0.0140 | 2021-07-21 |
CVE-2021-36294 UPD | 7.6 | 9.8 | 0.0156 | 2022-01-25 |
CVE-2021-41615 UPD | 7.6 | 9.8 | 0.0135 | 2022-08-08 |
CVE-2022-34294 UPD | 7.6 | 9.8 | 0.0147 | 2022-08-15 |
CVE-2023-49599 UPD | 7.5 | 9.8 | 0.0096 | 2024-01-10 |
CVE-2024-25730 UPD | 7.5 | 9.8 | 0.0086 | 2024-02-23 |
CVE-2024-47945 UPD | 7.5 | 9.8 | 0.0087 | 2024-10-15 |
CVE-2023-4344 UPD | 7.4 | 9.8 | 0.0059 | 2023-08-15 |
CVE-2025-47781 UPD | 7.4 | 9.8 | 0.0058 | 2025-05-14 |
CVE-2020-36925 UPD | 7.4 | 9.8 | 0.0060 | 2026-01-06 |
CVE-2025-66565 | 7.3 | 9.8 | 0.0046 | 2025-12-09 |
CVE-2026-38447 | 7.3 | 9.8 | 0.0046 | 2026-08-03 |
CVE-2024-36400 UPD | 7.2 | 9.4 | 0.0075 | 2024-06-04 |
CVE-2017-18883 UPD | 7.1 | 9.1 | 0.0112 | 2020-06-19 |
CVE-2021-4238 UPD | 7.1 | 9.1 | 0.0132 | 2022-12-27 |
CVE-2024-3411 UPD | 7.0 | 9.1 | 0.0072 | 2024-04-30 |