CVEbaza.plSłownik CWECWE-669
Common Weakness Enumeration

CWE-669

Incorrect Resource Transfer Between Spheres

Kategoria: ClassCVE: 111
Opis

Produkt nie przenosi prawidłowo zasobu/zachowania do innej sfery lub nieprawidłowo importuje zasób/zachowanie z innej sfery, w sposób który zapewnia niezamierzoną kontrolę nad tym zasobem. Może to prowadzić do naruszeń bezpieczeństwa poprzez nieautoryzowany dostęp lub manipulację zasobami.

Description (EN)

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Podatności CVE z CWE-669 (111)
9.9
CVSS
CRITICAL
CVE-2021-30120

Kaseya VSA przed wersją 9.5.7 umożliwia atakującemu całkowite pominięcie uwierzytelnienia dwuskładnikowego (2FA). Podatność jest krytyczna, ponieważ pozwala na przejęcie konta użytkownika posiadającego 2FA, o ile atakujący zna jego hasło.

pub. 2021-07-09
9.8
CVSS
CRITICAL
CVE-2025-67895

Podatność w Apache Airflow Providers Edge3 (wersje przed 2.0.0) umożliwia autorowi DAG wykonanie zdalnego kodu (RCE) w kontekście procesu webservera Airflow 2. Problem dotyczy wyłącznie instalacji, w których Edge3 provider był zainstalowany i skonfigurowany na Airflow 2.

pub. 2025-12-17
9.8
CVSS
CRITICAL
CVE-2022-4446

W aplikacji coreBOS przed wersją 8.0 odkryto podatność klasy PHP Remote File Inclusion (RFI), umożliwiającą zdalne wykonanie kodu bez konieczności uwierzytelnienia. Podatność otrzymała ocenę CVSS 9.8 (CRITICAL), co czyni ją ekstremalnie niebezpieczną dla każdego systemu opartego na tej platformie.

pub. 2022-12-13
9.8
CVSS
CRITICAL
CVE-2020-24683

Podatność w ABB Symphony+ Operations (wersja 2.1 SP1 i wcześniejsze) pozwala nieuwierzytelnionym atakującym na ominięcie mechanizmu uwierzytelnienia i nawiązanie nieautoryzowanego połączenia z serwerem aplikacji. Jest szczególnie groźna w środowiskach przemysłowych, gdzie systemy SCADA/HMI często nie są dostatecznie izolowane sieciowo.

pub. 2020-12-22
9.8
CVSS
CRITICAL
CVE-2020-5800

Aplikacja mobilna Eat Spray Love (iOS i Android) zawiera błąd logiczny umożliwiający obejście mechanizmu uwierzytelniania. Podatność jest krytyczna, ponieważ nieuwierzytelniony atakujący może zdalnie uzyskać dostęp lub modyfikować dane innych użytkowników.

pub. 2020-12-07
9.8
CVSS
CRITICAL
CVE-2020-15892

W urządzeniach D-Link DAP-1520 z firmware przed wersją 1.10b04Beta02 odkryto podatność stack-based buffer overflow w pliku apply.cgi, umożliwiającą zdalne przejęcie kontroli nad urządzeniem bez uwierzytelnienia. Podatność jest szczególnie groźna, ponieważ walidacja długości pola hasła odbywa się wyłącznie po stronie klienta i może zostać łatwo ominięta.

pub. 2020-07-22
9.8
CVSS
CRITICAL
CVE-2019-13025

Urządzenia Compal CH7465LG z oprogramowaniem CH7465LG-NCIP-6.12.18.24-5p8-NOSH są podatne na zdalne wykonanie poleceń systemowych (RCE) poprzez command injection w backendowym API modemu kablowego. Podatność jest krytyczna, ponieważ nie wymaga żadnego uwierzytelnienia ani interakcji użytkownika.

pub. 2019-10-02
9.8
CVSS
CRITICAL
CVE-2016-5062

Serwer web w Aternity przed wersją 9.0.1 nie wymaga uwierzytelnienia przy ładowaniu Java MBeans przez endpoint getMBeansFromURL. Umożliwia to zdalnemu atakującemu bez żadnych uprawnień wykonanie dowolnego kodu Java na serwerze.

pub. 2016-09-29
9.6
CVSS
CRITICAL
CVE-2022-20658

Podatność w interfejsie webowym Cisco Unified Contact Center Management Portal (Unified CCMP) i Cisco Unified Contact Center Domain Manager (Unified CCDM) pozwala uwierzytelnionemu zdalnemu atakującemu na podniesienie uprawnień do poziomu Administrator. Brak walidacji uprawnień użytkownika po stronie serwera czyni tę lukę szczególnie niebezpieczną w środowiskach contact center.

pub. 2022-01-14
9.1
CVSS
CRITICAL
CVE-2023-31114

W komponencie Shannon RCS modemów Samsung Exynos 5123 oraz 5300 wykryto podatność polegającą na nieprawidłowym transferze zasobów między sferami izolacji. Umożliwia ona niezamierzone odpytywanie statusu karty SIM za pomocą specjalnie spreparowanej aplikacji.

pub. 2023-06-07
8.8
CVSS
HIGH
CVE-2025-41660

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

pub. 2026-03-24
8.8
CVSS
HIGH
CVE-2026-25253

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

pub. 2026-02-01
8.8
CVSS
HIGH
CVE-2021-45891

An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all permission checks are done client-side, not server-side.

pub. 2022-04-05
8.8
CVSS
HIGH
CVE-2021-24602

The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page

pub. 2021-08-23
8.8
CVSS
HIGH
CVE-2020-25917

Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.

pub. 2020-12-26
8.8
CVSS
HIGH
CVE-2019-13263

D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.

pub. 2019-08-27
8.8
CVSS
HIGH
CVE-2019-13266

TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.

pub. 2019-08-27
8.8
CVSS
HIGH
CVE-2019-11875

In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate privileges. The vulnerability allows for abusing the application for fraud or unauthorized access to certain information. The attack requires a valid user account to connect to the Blue Prism server, but the roles associated to this account are not required to have any permissions. First of all, the application files are modified to grant full permissions on the client side. In a test environment (or his own instance of the software) an attacker is able to grant himself full privileges also on the server side. He can then, for instance, create a process with malicious behavior and export it to disk. With the modified client, it is possible to import the exported file as a release and overwrite any existing process in the database. Eventually, the bots execute the malicious process. The server does not check the user's permissions for the aforementioned actions, such that a modification of the client software enables this kind of attack. Possible scenarios may involve changing bank accounts or setting passwords.

pub. 2019-05-24
8.6
CVSS
HIGH
CVE-2025-41645

An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.

pub. 2025-05-13
8.5
CVSS
HIGH
CVE-2025-34158

Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner).

pub. 2025-08-21
Pokazano 20 z 111 podatności
Informacje
ID: CWE-669
Typ: Class
Podatności: 111
MITRE CWE ↗
← Słownik CWE