CVEbaza.plSłownik CWECWE-671
Common Weakness Enumeration

CWE-671

Lack of Administrator Control over Security

Kategoria: ClassCVE: 5
Opis

Produkt wykorzystuje funkcje bezpieczeństwa w sposób uniemożliwiający administratorowi dostosowanie ustawień bezpieczeństwa do środowiska, w którym produkt jest używany. Powoduje to powstanie potencjalnych podatności lub uniemożliwia działanie na pożądanym przez administratora poziomie bezpieczeństwa.

Description (EN)

The product uses security features in a way that prevents the product's administrator from tailoring security settings to reflect the environment in which the product is being used. This introduces resultant weaknesses or prevents it from operating at a level of security that is desired by the administrator.

Podatności CVE z CWE-671 (5)
9.1
CVSS
CRITICAL
CVE-2025-24024

Mjolnir v1.9.0 (narzędzie moderacyjne dla platformy Matrix) błędnie reaguje na komendy zarządzające z dowolnego pokoju, w którym bot jest obecny. Pozwala to nieautoryzowanym użytkownikom na wykonywanie funkcji bota, w tym komponentów administracji serwerem.

pub. 2025-01-21
8.8
CVSS
HIGH
CVE-2018-13283

Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, (2) hostname, or (3) port parameter.

pub. 2019-04-01
8.3
CVSS
HIGH
CVE-2026-31985

W konfiguracji generowanej przez narzędzie n2os-tui dla Remote Collector weryfikacja certyfikatu TLS była domyślnie wyłączona i nie istniała opcja jej włączenia. Umożliwia to przeprowadzenie ataku man-in-the-middle na komunikację między Remote Collector a Guardian lub CMC.

pub. 2026-07-09
5.4
CVSS
MEDIUM
CVE-2023-20115

A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device. This vulnerability is due to a logic error when verifying the user role when an SFTP connection is opened to an affected device. An attacker could exploit this vulnerability by connecting and authenticating via SFTP as a valid, non-administrator user. A successful exploit could allow the attacker to read or overwrite files from the underlying operating system with the privileges of the authenticated user. There are workarounds that address this vulnerability.

pub. 2023-08-23
3.5
CVSS
LOW
CVE-2022-29163

Nextcloud Server to oprogramowanie serwera plików dla Nextcloud, samodzielnie hostowanej platformy produktywności. Przed wersjami 22.2.6 i 23.0.3 użytkownik mógł utworzyć link niechroniony hasłem, nawet jeśli administrator wymagał ochrony hasłem dla wszystkich linków. Wersje 22.2.6 i 23.0.3 zawierają poprawkę dla tego problemu. Obecnie nie są znane żadne obejścia.

pub. 2022-05-20
Informacje
ID: CWE-671
Typ: Class
Podatności: 5
MITRE CWE ↗
← Słownik CWE