Cyber Risk Compendium

Software vulnerabilities or errors

BSI ID: G 0.28

The following applies to all software: the more complex it is, the more frequently errors occur. Even with intensive testing, it is usually not possible to detect all errors before delivery to customers. If software errors are not detected in time, crashes or errors occurring during use can have far-reaching consequences. Examples include incorrect calculation results, wrong decisions at management level and delays in business processes. Software vulnerabilities or errors can lead to serious security gaps in an application, an IT system or all IT systems connected to it. Such security gaps can potentially be exploited by attackers to inject malware, read data without authorisation or manipulate data.

Examples:

  • Most of the warnings issued by computer emergency response teams (CERTs) in recent years have related to security-related programming errors. These are errors that occur during the creation of software and result in the software being misused by attackers. A large proportion of these errors were caused by buffer overflows.

  • Internet browsers are now an important software component on clients. Browsers are often used not only to access the Internet, but also for internal web applications in companies and public authorities. Software vulnerabilities or errors in browsers can therefore have a particularly serious impact on overall information security.