CVEbaza.plSłownik CWECWE-923
Common Weakness Enumeration

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints

Kategoria: ClassCVE: 68
Opis

Produkt nawiązuje kanał komunikacji do (lub z) punktu końcowego w celu wykonania operacji uprzywilejowanych lub chronionych, jednak nie zapewnia prawidłowo, że komunikuje się z prawidłowym punktem końcowym. Ta luka umożliwia atakującemu przechwycenie lub przekierowanie komunikacji do nieautoryzowanego celu.

Description (EN)

The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Podatności CVE z CWE-923 (68)
10.0
CVSS
CRITICAL
CVE-2019-17440

Podatność w urządzeniach PA-7050 i PA-7080 z zainstalowaną kartą Log Forwarding Card (LFC) i kartą zarządzającą drugiej generacji (SMC) pozwala atakującemu z dostępem sieciowym do LFC uzyskać uprawnienia root w systemie PAN-OS. Podatność uzyskała maksymalną ocenę CVSS 10.0, co czyni ją krytycznie niebezpieczną.

pub. 2019-12-20
9.8
CVSS
CRITICAL
CVE-2024-41889

Produkty Pimax akceptują połączenia WebSocket od nieuprawnionych punktów końcowych, co umożliwia zdalnemu, nieuwierzytelnionemu atakującemu wykonanie dowolnego kodu. Podatność jest krytyczna ze względu na brak wymagań uwierzytelnienia i możliwość pełnego przejęcia kontroli nad systemem.

pub. 2024-08-05
9.6
CVSS
CRITICAL
CVE-2026-34205

Aplikacje (add-ony) Home Assistant skonfigurowane w trybie sieci hosta eksponują nieuwierzytelnione endpointy powiązane z wewnętrznym interfejsem Docker bridge na sieć lokalną. Każde urządzenie w tej samej sieci może uzyskać dostęp do tych endpointów bez żadnego uwierzytelnienia, co stanowi poważne zagrożenie dla bezpieczeństwa instalacji.

pub. 2026-03-27
9.6
CVSS
CRITICAL
CVE-2017-3891

Podatność w BlackBerry QNX Software Development Platform 6.6.0 z włączonym protokołem QNet pozwala atakującemu na nieuprawniony dostęp do plików i przejęcie ich własności na dowolnych węzłach sieci QNet. Zagrożenie jest krytyczne, ponieważ nie wymaga uwierzytelnienia ani interakcji użytkownika.

pub. 2017-11-14
9.1
CVSS
CRITICAL
CVE-2023-28078

Przełączniki sieciowe Dell OS10 w wersjach 10.5.2.x i nowszych z włączoną konfiguracją VLT zawierają podatność w komponencie zeroMQ, umożliwiającą zdalnemu, nieuwierzytelnionemu atakującemu uzyskanie dostępu do wrażliwych danych oraz wywołanie Denial of Service. Podatność jest szczególnie niebezpieczna ze względu na brak wymogu uwierzytelnienia i sieciowy wektor ataku.

pub. 2024-02-15
8.8
CVSS
HIGH
CVE-2025-20261

A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient restrictions on access to internal services. An attacker with a valid user account could exploit this vulnerability by using crafted syntax when connecting to the Cisco IMC of an affected device through SSH. A successful exploit could allow the attacker to access internal services with elevated privileges, which may allow unauthorized modifications to the system, including the possibility of creating new administrator accounts on the affected device.

pub. 2025-06-04
8.8
CVSS
HIGH
CVE-2021-38487

RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.

pub. 2022-05-05
8.7
CVSS
HIGH
CVE-2026-62836

Podatność w Azure SQL Managed Instance pozwala nieuwierzytelnionemu atakującemu na eskalację uprawnień poprzez sieć. Zagrożenie jest poważne, gdyż exploit nie wymaga żadnej interakcji użytkownika ani posiadania wcześniejszych uprawnień.

pub. 2026-08-07
8.7
CVSS
HIGH
CVE-2025-61939

An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.

pub. 2026-01-07
8.5
CVSS
HIGH
CVE-2026-8920

Podatność w usłudze Aura Wallpaper Service firmy ASUS umożliwia lokalnemu użytkownikowi wykonywanie nieautoryzowanych operacji na plikach przez ominięcie ograniczeń ścieżek. Błąd wynika z braku właściwej weryfikacji kanału komunikacji oraz zewnętrznej kontroli nad nazwą lub ścieżką pliku.

pub. 2026-07-15
8.5
CVSS
HIGH
CVE-2025-58742

Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.

pub. 2026-01-20
8.4
CVSS
HIGH
CVE-2024-26131

Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Possible impact includes making Element Android display an arbitrary web page, executing arbitrary JavaScript; bypassing PIN code protection; and account takeover by spawning a login screen to send credentials to an arbitrary home server. This issue is fixed in Element Android 1.6.12. There is no known workaround to mitigate the issue.

pub. 2024-02-29
8.3
CVSS
HIGH
CVE-2025-29986

Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Common Anti-Virus Agent (CAVA). An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

pub. 2025-04-08
7.7
CVSS
HIGH
CVE-2024-47490

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network based attacker to cause increased consumption of resources, ultimately resulting in a Denial of Service (DoS). When specific transit MPLS packets are received by the PFE, these packets are internally forwarded to the Routing Engine (RE), rather than being handled appropriately. Continuous receipt of these MPLS packets causes resources to be exhausted. MPLS config is not required to be affected by this issue.  This issue affects Junos OS Evolved ACX 7000 Series:  * All versions before 21.4R3-S9-EVO, * 22.2-EVO before 22.2R3-S4-EVO,  * 22.3-EVO before 22.3R3-S3-EVO,  * 22.4-EVO before 22.4R3-S2-EVO,  * 23.2-EVO before 23.2R2-EVO,  * 23.4-EVO before 23.4R1-S1-EVO, 23.4R2-EVO.

pub. 2024-10-11
7.6
CVSS
HIGH
CVE-2026-32303

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint. Impacted are users unlocking Hub-backed vaults with affected client versions in environments where an attacker can alter the vault.cryptomator file. This issue has been patched in version 1.19.1.

pub. 2026-03-20
7.6
CVSS
HIGH
CVE-2026-32317

Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint. Impacted are users unlocking Hub-backed vaults with affected client versions in environments where an attacker can alter the vault.cryptomator file. This issue has been patched in version 1.12.3.

pub. 2026-03-20
7.6
CVSS
HIGH
CVE-2026-32318

Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint. Impacted are users unlocking Hub-backed vaults with affected client versions in environments where an attacker can alter the vault.cryptomator file. This issue has been patched in version 2.8.3.

pub. 2026-03-20
7.6
CVSS
HIGH
CVE-2025-23178

CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

pub. 2025-04-29
7.6
CVSS
HIGH
CVE-2024-47125

The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to the current release for enhanced encryption protocols.

pub. 2024-09-26
7.5
CVSS
HIGH
CVE-2026-59841

Podatność w Fortinet FortiSIEM Windows Agent polega na nieprawidłowym ograniczeniu kanału komunikacyjnego do zamierzonych punktów końcowych, co może umożliwić atakującemu eskalację uprawnień. Dotyczy wersji 7.4.0 oraz 7.4.1 agenta działającego na systemie Windows.

pub. 2026-07-14
Pokazano 20 z 68 podatności
Informacje
ID: CWE-923
Typ: Class
Podatności: 68
MITRE CWE ↗
← Słownik CWE