Skip to main content
Common Weakness Enumeration

Common Weakness Enumeration

Search complete. 36 mentions across 11 episodes found for "Common Weakness Enumeration".

Oct 1, 2026

NeilHOST
4:43
That benchmark specifically tests long video understanding.
AlexHOST
4:47
Then there is the CWE-Bench version one.
AlexHOST
4:50
Argon tied GPT-6 Astra for first place there.
AlexHOST
4:53
That benchmark specifically tests complex vulnerability remediation in codebases.
Mike SchemaHOST
0:12
Those scores are assigned to CVEs, which are common vulnerability enumerations that turn bugs into unique identifiers.
Mike SchemaHOST
0:19
And all those vols share almost universal underlying problems that we call CWEs that turn all that bug tracking into completely wasted efforts.
Mike SchemaHOST
0:29
And so this week we chat with Shlomi Liebrow about bug bounties, LLMs, agents, and the changing nature of finding flaws.
Mike SchemaHOST
0:38
Be less common and stay tuned for Application Security Weekly.
Mike SchemaHOST
0:12
Those scores are assigned to CVEs, which are common vulnerability enumerations that turn bugs into unique identifiers.
Mike SchemaHOST
0:19
And all those vulns share almost universal underlying problems that we call CWEs, that turn all that bug tracking into completely wasted efforts.
Mike SchemaHOST
0:29
And so, this week, we chat with Shlomi Librov about bug bounties, LLMs, agents, and the changing nature of finding flaws.
Mike SchemaHOST
0:38
Be less common and stay tuned for Application Security Weekly.
Allan FriedmanGUEST
50:02
And I think one, good security people have been doing that.
Allan FriedmanGUEST
50:07
I'll give a shout out to a gentleman that I mentored for B-Sides Las Vegas this year, gave a talk where he just found a class of vulnerabilities, a CWE, for you implemented the crypto library wrong, you idiot.
Allan FriedmanGUEST
50:28
Uh, you accidentally did a check that would go positive on a null seed rather than reject a null seed.
Allan FriedmanGUEST
50:38
Uh, right.
speaker_2HOST
3:21
Exactly.
speaker_2HOST
3:21
So the core issue here, classified under the official Common Weakness Enumeration Catalog, is CWE-822.
speaker_2HOST
3:29
It is an untrusted pointer to reference.
speaker_1HOST
3:31
OK, so break that down for us, because since this is an untrusted pointer to reference, the real issue here isn't just a basic memory crash.

32 MINS LATER

speaker_2HOST
35:24
But let me push back on this because I want to look at the raw evidence of the threat.
speaker_2HOST
35:28
If we accept that we can't lock down those local interfaces immediately without breaking the car or stopping the assembly line, What is the actual risk we are living with? If we leave those USB ports and Bluetooth connections wide open today, what happens when an attacker actually exploits this untrusted pointer to reference?
speaker_1HOST
35:49
To understand the real world impact, we really need to strip away the jargon from the manual sources analysis of CWE-822, which is the underlying weakness here.
speaker_1HOST
35:59
An untrusted pointer to reference sounds incredibly abstract, but let's break it down.
speaker_1HOST
3:05
Right.
speaker_1HOST
3:05
Which brings me to the threat landscape, because I was looking at the recently updated 2025 CWE most important hardware weaknesses list.
speaker_2HOST
3:14
Oh, the MIHW.
speaker_2HOST
3:15
Yeah, that list has gotten really interesting lately.
speaker_1HOST
3:18
It has, especially the emerging threats that, you know, didn't even exist a few years ago.
speaker_1HOST
3:22
Like I'm looking at CWE 1234.
speaker_2HOST
3:25
Right, the internal debug modes?
speaker_1HOST
3:27
Yeah, where hardware internal or debug modes basically allow an override of locks.
speaker_1HOST
19:17
Exactly.
speaker_1HOST
19:18
So in software security, vulnerabilities are categorized by the Common Weakness Enumeration, or CWE.
speaker_1HOST
19:25
And this particular air wall vulnerability is classified under CWE-321.
speaker_2HOST
19:30
OK, what does that mean exactly?
speaker_2HOST
4:34
And the data strongly validates that perspective too.
speaker_2HOST
4:36
If you look at the common weakness enumeration list, the CWE database specifically tailored for hardware, it is filled with these exact types of logical issues.
speaker_1HOST
4:45
Like what? Give me an example of a logical hardware flaw.
speaker_2HOST
4:48
Well, a classic example is a power state transition flaw.

44 MINS LATER

speaker_2HOST
48:51
Because if that verification fails, the consequences aren't just a software bug.
speaker_2HOST
48:55
They are catastrophic.
speaker_1HOST
48:56
And looking at the 2025 Common Weakness Enumeration, the CWE insights, we get a terrifying look at what those hardware failures actually are.
speaker_1HOST
49:05
The CWE highlights the most critical hardware weaknesses, and these are permanent physical flaws.
speaker_2HOST
3:57
Mm-hmm.
speaker_1HOST
3:57
The advisory classifies this as a CWE seventy-eight, which is an OS command injection flaw.
speaker_2HOST
4:02
Yep.
speaker_1HOST
4:02
And that allows an unauthenticated attacker to execute arbitrary code with root privileges straight through the router's web management interface.
speaker_1HOST
7:03
It completely subverts the entire concept of authentication.
speaker_1HOST
7:06
Why on earth would anyone design a security device to do that?
speaker_2HOST
7:09
Well, it is classified as a CWE 288, an authentication bypass using an alternate path or channel.
speaker_2HOST
7:16
But to answer your question, we really have to look at this with a bit of empathy for the OT engineers.
HezHOST
10:41
But it's manifesting in a highly complex, modern physical security environment.
HezHOST
10:48
So the core mechanism driving this entire vulnerability is designated as CWE78.
speaker_1HOST
10:53
In
HezHOST
10:54
the cybersecurity world, that translates to an OS command injection flaw.

5 MINS LATER

HezHOST
16:21
That is a phenomenal analogy, actually.
HezHOST
16:24
That is exactly what is happening with the system shell.
HezHOST
16:27
Let's walk through a specific example from the CWE78 source material on how these injection flaws typically operate.
speaker_1HOST
16:34
Walk me through it.

1 more episode mentions Common Weakness Enumeration.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.