CWE-1105 Base Incompleto

Insufficient Encapsulation of Machine-Dependent Functionality

This weakness occurs when an application relies on hardware-specific or platform-dependent features but fails to isolate that code from the rest of the system. This poor separation creates tight…

Definição

What is CWE-1105?

This weakness occurs when an application relies on hardware-specific or platform-dependent features but fails to isolate that code from the rest of the system. This poor separation creates tight coupling between the core logic and low-level machine details.
When machine-dependent code—like direct hardware manipulation, processor-specific instructions, or OS-native calls—is scattered throughout an application, it creates a maintenance burden. Porting the software to a new architecture or platform becomes a complex, error-prone task of finding and updating every embedded dependency. This directly slows down development cycles and makes applying security patches more difficult. Indirectly, this complexity becomes a security liability. The increased effort to maintain or migrate the code makes it harder to identify and fix vulnerabilities in a timely manner. Developers are more likely to introduce flaws when modifying this entangled code, and the lack of clear boundaries can obscure security-critical logic. Properly encapsulating these dependencies behind clean interfaces is essential for long-term security and maintainability.
Impacto no mundo real

Real-world CVEs caused by CWE-1105

Ainda não há referências CVE públicas associadas a este CWE no catálogo da MITRE.

Como os atacantes a exploram

Trajeto do atacante passo a passo

  1. 1

    Identificar um caminho de código que trata input não confiável sem validação.

  2. 2

    Criar um payload que explora o comportamento inseguro — injeção, traversal, overflow ou abuso de lógica.

  3. 3

    Entregar o payload através de um pedido normal e observar a reação da aplicação.

  4. 4

    Iterar até que a resposta exponha dados, execute código do atacante ou escale privilégios.

Exemplo de código vulnerável

Vulnerable C

In this example function, the memory address of variable b is derived by adding 1 to the address of variable a. This derived address is then used to assign the value 0 to b.

Vulnerável C
void example() {
  	char a;
  	char b;
  	*(&a + 1) = 0;
  }
Exemplo de código seguro

Secure pseudo

Seguro pseudo
// Validate, sanitize, or use a safe API before reaching the sink.
function handleRequest(input) {
  const safe = validateAndEscape(input);
  return executeWithGuards(safe);
}
What changed: the unsafe sink is replaced (or the input is validated/escaped) so the same payload no longer triggers the weakness.
Lista de verificação de prevenção

How to prevent CWE-1105

  • Architecture Use safe-by-default frameworks and APIs that prevent the unsafe pattern from being expressible.
  • Implementation Validate input at trust boundaries; use allowlists, not denylists.
  • Implementation Apply the principle of least privilege to credentials, file paths, and runtime permissions.
  • Testing Cover this weakness in CI: SAST rules + targeted unit tests for the data flow.
  • Operation Monitor logs for the runtime signals listed in the next section.
Sinais de deteção

How to detect CWE-1105

SAST High

Executar análise estática (SAST) na base de código à procura do padrão inseguro no fluxo de dados.

DAST Moderate

Executar testes dinâmicos de segurança de aplicações (DAST) contra o endpoint em execução.

Runtime Moderate

Monitorizar os registos em tempo de execução para traços de exceção invulgares, input malformado ou tentativas de contornar a autorização.

Code review Moderate

Revisão de código: sinalizar qualquer novo código que trate input desta superfície sem usar os ajudantes validados do framework.

CWE-1105

Don't catalog this weakness. Prove it's reachable.

Plexicus turns CWE catalogs into evidence: every CWE-pattern is matched against your real code graph, reach is proven on a sandbox clone, and verified findings ship as reviewed PRs.

Perguntas frequentes

Frequently asked questions

O que é o CWE-1105?

This weakness occurs when an application relies on hardware-specific or platform-dependent features but fails to isolate that code from the rest of the system. This poor separation creates tight coupling between the core logic and low-level machine details.

Qual a gravidade do CWE-1105?

A MITRE não publicou uma classificação de probabilidade de exploração para esta fraqueza. Trate-a como impacto médio até o seu modelo de ameaças provar o contrário.

Que linguagens ou plataformas são afetadas pelo CWE-1105?

A MITRE não especificou as plataformas afetadas por este CWE — pode aplicar-se à maioria das stacks de aplicações.

Como posso prevenir o CWE-1105?

Use safe-by-default frameworks, validate untrusted input at trust boundaries, and apply the principle of least privilege. Cover the data-flow signature in CI with SAST.

Como é que o Plexicus deteta e corrige o CWE-1105?

O motor SAST do Plexicus correlaciona a assinatura de fluxo de dados do CWE-1105 em cada commit. Quando é encontrada uma correspondência, o nosso agente Codex Remedium abre um PR de correção com o código corrigido, testes e um resumo de uma linha para o revisor.

Onde posso saber mais sobre o CWE-1105?

A MITRE publica a definição canónica em https://cwe.mitre.org/data/definitions/1105.html. Pode também consultar a documentação da OWASP e do NIST para orientações adjacentes.

Fraquezas relacionadas

Weaknesses related to CWE-1105

CWE-758 Pai

Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

This weakness occurs when software depends on specific behaviors of an API, data structure, or system component that are not formally…

CWE-1038 Irmão

Insecure Automated Optimizations

This vulnerability occurs when software uses automated tools to optimize code for performance or efficiency, but those optimizations…

CWE-1102 Irmão

Reliance on Machine-Dependent Data Representation

This weakness occurs when software directly depends on how a specific machine, processor, or operating system represents data in memory.…

CWE-1103 Irmão

Use of Platform-Dependent Third Party Components

This weakness occurs when software depends on third-party libraries or components that behave differently or lack support across various…

CWE-474 Irmão

Use of Function with Inconsistent Implementations

This vulnerability occurs when code relies on a function whose behavior changes across different operating systems or versions, leading to…

CWE-562 Irmão

Return of Stack Variable Address

This vulnerability occurs when a function returns a pointer to its own local variable. Since that variable's memory is on the stack, the…

CWE-587 Irmão

Assignment of a Fixed Address to a Pointer

This vulnerability occurs when code explicitly assigns a hardcoded memory address to a pointer, instead of using a dynamic or null value.

CWE-588 Irmão

Attempt to Access Child of a Non-structure Pointer

This vulnerability occurs when code incorrectly treats a pointer to a basic data type (like an integer) as if it points to a structured…

CWE-188 Filho

Reliance on Data/Memory Layout

This vulnerability occurs when software incorrectly assumes how data is structured in memory or within network packets, leading to…

Pronto para validar o que importa?

Pronto para validar o que importa.

O Plexicus é Proof-Driven AppSec: achados validados, compreensão contextual e remediação revisada — ancorada em evidência, escopada com você.

Qualificação

Verifique se o AI Swarm Pentest se adequa ao seu ambiente.

Partilhe o contexto mínimo. Vamos rever o escopo e indicar o próximo passo comercial.

Antes de enviar — verifique se se encaixa

0 / 280

Sem compromisso. Se não se encaixa, dizemos.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorized target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)
Ronda privada Para investidores