CVEbaza.plSłownik CWECWE-1125
Common Weakness Enumeration

CWE-1125

Excessive Attack Surface

Kategoria: BaseCVE: 5
Opis

Produkt posiada powierzchnię ataku, której pomiar ilościowy przekracza pożądane maksimum. Oznacza to, że liczba potencjalnych punktów dostępu dla atakujących jest zbyt duża i stanowi znaczące zagrożenie dla bezpieczeństwa.

Description (EN)

The product has an attack surface whose quantitative measurement exceeds a desirable maximum.

Podatności CVE z CWE-1125 (5)
9.8
CVSS
CRITICAL
CVE-2023-0435

W repozytorium GitHub projektu pyload/pyload, w wersjach poprzedzających 0.5.0b3.dev41, zidentyfikowano podatność sklasyfikowaną jako nadmierna powierzchnia ataku (Excessive Attack Surface). Podatność uzyskała ocenę CVSS 9.8 (CRITICAL), co wskazuje na możliwość poważnych konsekwencji bez konieczności uwierzytelnienia.

pub. 2023-01-22
9.8
CVSS
CRITICAL
CVE-2022-1715

W aplikacji Facturascripts w wersjach wcześniejszych niż 2022.07 istnieje krytyczna podatność umożliwiająca przejęcie konta dowolnego użytkownika bez uwierzytelnienia. Ze względu na maksymalny wpływ na poufność, integralność i dostępność, luka stanowi poważne zagrożenie dla organizacji korzystających z tego oprogramowania.

pub. 2022-05-13
8.8
CVSS
HIGH
CVE-2024-5386

In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijack another user's account by obtaining the password reset token. The vulnerability is triggered when the 'viewer' role user sends a specific request to the server, which responds with a password reset token in the 'recoveryToken' parameter. This token can then be used to reset the password of another user's account without authorization. The issue results from an excessive attack surface, allowing lower-privileged users to escalate their privileges and take over accounts.

pub. 2026-02-02
8.3
CVSS
HIGH
CVE-2023-49722

Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.

pub. 2024-01-09
8.0
CVSS
HIGH
CVE-2022-2037

Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.

pub. 2022-06-09
Informacje
ID: CWE-1125
Typ: Base
Podatności: 5
MITRE CWE ↗
← Słownik CWE