EVP_des_cbc

c · standard library
sinkDerived from model facts
RoleSink
WeaknessCWE-327 · CWE-326
WatchesReturnValue
Kindweak-crypto
Confidencehigh
Corroboration2

Sink boundary: A cryptographic primitive is modeled because its strength may not meet the security property required by the caller.

Argument map · what each slot does

The pack does not provide a callable signature for this record; the watched access path is shown directly.

No positional argument is specified; inspect the return value or named access path in the model facts below.
The weakness
CWE-327
Broken or Risky Cryptographic Algorithm

A broken or risky cryptographic algorithm or protocol is used.

CWE-326
Inadequate Encryption Strength

Sensitive data uses encryption that is weaker than the required protection level.

What goes wrong
Attacker's-eye view · weak-crypto

An attacker exploits weak hashing, encryption, or protocol choices to recover or forge values.

// modeled boundary: ReturnValue EVP_des_cbc(attacker_influenced_value);
To decide if this call is a bug, check
1Identify the property the primitive is meant to provide.
2Use current, reviewed algorithms and parameters.
3Check key, nonce, and mode handling.
These checks require the surrounding codebase. The model names the boundary; it does not decide reachability or prove that a guard dominates every path.
Is this a bug in your code?Atropos stops here — by design

Atropos identifies ReturnValue as a weak-crypto sink. It cannot see whether untrusted data reaches this call in your repository.

Lachesis is the codebase-level step: it traces reachability and guards for this symbol.

Check this symbol in Lachesis
The family · weak-crypto
Model facts · verbatim from the pack
RoleKindAccess pathModel IDConfidence
sinkweak-cryptoReturnValuec.openssl.evpdescbc.rethigh · corrob. 2