Cyber Resilience

CWE · MITRE source

CWE-338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Abstraction: Base · CVEs in our corpus: 211

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

When a non-cryptographic PRNG is used in a cryptographic context, it can expose the cryptography to certain types of attacks. Often a pseudo-random number generator (PRNG) is not designed for cryptography. Sometimes a mediocre source of randomness is sufficient or preferable for algorithms that use random numbers. Weak generators generally take less processing power and/or do not use the precious, finite, entropy sources on a system. While such PRNGs might have very useful features, these same features could be used to break the cryptography.

Last updated: 22 August 2026 14:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 3 mapping(s) from 3 framework(s): STIG oracle linux 8 1 (mostly) · STIG ubuntu 22 04 1 (mostly) · STIG rhel 8 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A04:2025 Cryptographic Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • AT-5 Contacts with Security Groups and Associations
  • SC-12 Cryptographic Key Establishment and Management
  • PR.PS-06
  • SC-13 Cryptographic Protection
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 3 hardening rules · 3 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V7.2.3
  • V11.5.1

NIST 800-53 r5 controls that address this weakness (2)AI-assisted

Control Title Family Why it addresses this CWE
AT-5Contacts with Security Groups and AssociationsATSecurity associations share details on cryptographically weak PRNGs, helping avoid their implementation in security-critical functions.
SC-12Cryptographic Key Establishment and ManagementSCCryptographic key management standards require cryptographically strong PRNGs for key material, blocking use of weak generators.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2009-2367 8.69.80.23192009-07-08
CVE-2008-0166 8.47.50.70722008-05-13
CVE-2019-16303 7.89.80.03672019-09-14
CVE-2017-18021 7.79.80.02362018-01-05
CVE-2015-9435 7.79.80.02062019-09-26
CVE-2020-28642 7.79.80.02552020-11-16
CVE-2021-3538 7.79.80.02312021-06-02
CVE-2024-29868 7.69.10.06002024-06-24
CVE-2019-14480 7.59.80.01122020-12-16
CVE-2011-4574 7.59.80.01092021-10-27
CVE-2023-36993 7.59.80.00962023-07-07
CVE-2024-40762 7.59.80.01042025-01-09
CVE-2022-44796 7.49.80.00692022-11-07
CVE-2023-2884 7.49.80.00692023-05-25
CVE-2025-3495 7.49.80.00672025-04-16
CVE-2025-59390 7.49.80.00612025-11-26
CVE-2026-615007.49.80.00752026-07-13
CVE-2025-7394 7.39.80.00392025-07-18
CVE-2025-665657.39.80.00462025-12-09
CVE-2025-689327.39.80.00532025-12-27
CVE-2026-2439 7.39.80.00402026-02-16
CVE-2025-409267.39.80.00432026-03-05
CVE-2025-156047.39.80.00522026-03-28
CVE-2026-3256 7.39.80.00532026-03-28
CVE-2026-561417.39.80.00522026-06-19