
Common Weakness Enumeration
36
MENTIONS
11
EPISODES
6
PODCASTS
Search complete. 36 mentions across 11 episodes found for "Common Weakness Enumeration".
Oct 1, 2026
🎙 EP 367: Google Launches Gemini 4 Argon & Dyna Unveils Taku Humanoid
N
4:43NeilHOST
That benchmark specifically tests long video understanding.
A
4:47AlexHOST
Then there is the CWE-Bench version one.
A
4:50AlexHOST
Argon tied GPT-6 Astra for first place there.
A
4:53AlexHOST
That benchmark specifically tests complex vulnerability remediation in codebases.
Going From Bug Bounty Bugs to More Secure Systems - Shlomie Liberow - ASW #402
M
0:12Mike SchemaHOST
Those scores are assigned to CVEs, which are common vulnerability enumerations that turn bugs into unique identifiers.
M
0:19Mike SchemaHOST
And all those vols share almost universal underlying problems that we call CWEs that turn all that bug tracking into completely wasted efforts.
M
0:29Mike SchemaHOST
And so this week we chat with Shlomi Liebrow about bug bounties, LLMs, agents, and the changing nature of finding flaws.
M
0:38Mike SchemaHOST
Be less common and stay tuned for Application Security Weekly.
Going From Bug Bounty Bugs to More Secure Systems - Shlomie Liberow - ASW #402
M
0:12Mike SchemaHOST
Those scores are assigned to CVEs, which are common vulnerability enumerations that turn bugs into unique identifiers.
M
0:19Mike SchemaHOST
And all those vulns share almost universal underlying problems that we call CWEs, that turn all that bug tracking into completely wasted efforts.
M
0:29Mike SchemaHOST
And so, this week, we chat with Shlomi Librov about bug bounties, LLMs, agents, and the changing nature of finding flaws.
M
0:38Mike SchemaHOST
Be less common and stay tuned for Application Security Weekly.
The BOM Explosion & Why PQC Stopped Being 10 Years Away with David Pollak & Allan Friedman
A
50:02Allan FriedmanGUEST
And I think one, good security people have been doing that.
A
50:07Allan FriedmanGUEST
I'll give a shout out to a gentleman that I mentored for B-Sides Las Vegas this year, gave a talk where he just found a class of vulnerabilities, a CWE, for you implemented the crypto library wrong, you idiot.
A
50:28Allan FriedmanGUEST
Uh, you accidentally did a check that would go positive on a null seed rather than reject a null seed.
A
50:38Allan FriedmanGUEST
Uh, right.
Local Does Not Mean Low Impact: CVE-2026-24083 and Automotive Attack Feasibility
S
3:21speaker_2HOST
Exactly.
S
3:21speaker_2HOST
So the core issue here, classified under the official Common Weakness Enumeration Catalog, is CWE-822.
S
3:29speaker_2HOST
It is an untrusted pointer to reference.
S
3:31speaker_1HOST
OK, so break that down for us, because since this is an untrusted pointer to reference, the real issue here isn't just a basic memory crash.
32 MINS LATER
S
35:24speaker_2HOST
But let me push back on this because I want to look at the raw evidence of the threat.
S
35:28speaker_2HOST
If we accept that we can't lock down those local interfaces immediately without breaking the car or stopping the assembly line, What is the actual risk we are living with? If we leave those USB ports and Bluetooth connections wide open today, what happens when an attacker actually exploits this untrusted pointer to reference?
S
35:49speaker_1HOST
To understand the real world impact, we really need to strip away the jargon from the manual sources analysis of CWE-822, which is the underlying weakness here.
S
35:59speaker_1HOST
An untrusted pointer to reference sounds incredibly abstract, but let's break it down.
Security Sign-Off for Silicon: Why Chip Security Must Become a Design Gate
S
3:05speaker_1HOST
Right.
S
3:05speaker_1HOST
Which brings me to the threat landscape, because I was looking at the recently updated 2025 CWE most important hardware weaknesses list.
S
3:14speaker_2HOST
Oh, the MIHW.
S
3:15speaker_2HOST
Yeah, that list has gotten really interesting lately.
S
3:18speaker_1HOST
It has, especially the emerging threats that, you know, didn't even exist a few years ago.
S
3:22speaker_1HOST
Like I'm looking at CWE 1234.
S
3:25speaker_2HOST
Right, the internal debug modes?
S
3:27speaker_1HOST
Yeah, where hardware internal or debug modes basically allow an override of locks.
One Hardcoded Key, Many Systems at Risk: The Johnson Controls Airwall Lesson
S
19:17speaker_1HOST
Exactly.
S
19:18speaker_1HOST
So in software security, vulnerabilities are categorized by the Common Weakness Enumeration, or CWE.
S
19:25speaker_1HOST
And this particular air wall vulnerability is classified under CWE-321.
S
19:30speaker_2HOST
OK, what does that mean exactly?
Beyond Software Supply Chains: NSA ASIC Assurance and the Problem of Trusting Silicon
S
4:34speaker_2HOST
And the data strongly validates that perspective too.
S
4:36speaker_2HOST
If you look at the common weakness enumeration list, the CWE database specifically tailored for hardware, it is filled with these exact types of logical issues.
S
4:45speaker_1HOST
Like what? Give me an example of a logical hardware flaw.
S
4:48speaker_2HOST
Well, a classic example is a power state transition flaw.
44 MINS LATER
S
48:51speaker_2HOST
Because if that verification fails, the consequences aren't just a software bug.
S
48:55speaker_2HOST
They are catastrophic.
S
48:56speaker_1HOST
And looking at the 2025 Common Weakness Enumeration, the CWE insights, we get a terrifying look at what those hardware failures actually are.
S
49:05speaker_1HOST
The CWE highlights the most critical hardware weaknesses, and these are permanent physical flaws.
When the Security Router Becomes the Attack Path: Weidmüller and the Fragility of Industrial Segmentation
S
3:57speaker_2HOST
Mm-hmm.
S
3:57speaker_1HOST
The advisory classifies this as a CWE seventy-eight, which is an OS command injection flaw.
S
4:02speaker_2HOST
Yep.
S
4:02speaker_1HOST
And that allows an unauthenticated attacker to execute arbitrary code with root privileges straight through the router's web management interface.
S
7:03speaker_1HOST
It completely subverts the entire concept of authentication.
S
7:06speaker_1HOST
Why on earth would anyone design a security device to do that?
S
7:09speaker_2HOST
Well, it is classified as a CWE 288, an authentication bypass using an alternate path or channel.
S
7:16speaker_2HOST
But to answer your question, we really have to look at this with a bit of empathy for the OT engineers.
When Edit Permissions Become System-Level Code Execution
H
10:41HezHOST
But it's manifesting in a highly complex, modern physical security environment.
H
10:48HezHOST
So the core mechanism driving this entire vulnerability is designated as CWE78.
S
10:53speaker_1HOST
In
H
10:54HezHOST
the cybersecurity world, that translates to an OS command injection flaw.
5 MINS LATER
H
16:21HezHOST
That is a phenomenal analogy, actually.
H
16:24HezHOST
That is exactly what is happening with the system shell.
H
16:27HezHOST
Let's walk through a specific example from the CWE78 source material on how these injection flaws typically operate.
S
16:34speaker_1HOST
Walk me through it.
1 more episode mentions Common Weakness Enumeration.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.