Cyber Posture

CWE · MITRE source

CWE-332Insufficient Entropy in PRNG

Abstraction: Variant · CVEs in our corpus: 10

The lack of entropy available for, or used by, a Pseudo-Random Number Generator (PRNG) can be a stability and security threat.

Last updated: 19 May 2026 22:20 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SC-12Cryptographic Key Establishment and ManagementSCManaged key generation relies on PRNGs seeded and operated with adequate entropy, avoiding the listed weakness.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2018-90572.09.80.00462018-03-27
CVE-2016-9154 UPD1.67.50.01172016-12-23
CVE-2014-9690 UPD1.57.50.00182017-04-02
CVE-2016-107431.57.50.00432019-03-23
CVE-2017-184861.57.20.01592019-08-09
CVE-2023-201071.57.50.00502023-03-23
CVE-2019-17151.15.30.00402019-05-03
CVE-2017-9371 UPD0.52.60.00242017-11-14
CVE-2014-00160.00.00.00312014-03-24
CVE-2026-32900.00.00.00022026-05-14