CVEbaza.plSłownik CWECWE-941
Common Weakness Enumeration

CWE-941

Incorrectly Specified Destination in a Communication Channel

Kategoria: BaseCVE: 11
Opis

Produkt tworzy kanał komunikacyjny w celu zainicjowania wychodzącego żądania do aktora, ale nie określa prawidłowo zamierzonego celu dla tego aktora. Powoduje to potencjalnie wysłanie informacji do niewłaściwego adresata.

Description (EN)

The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.

Podatności CVE z CWE-941 (11)
9.4
CVSS
CRITICAL
CVE-2024-34947

Urządzenie IK-Q3000 firmy Quanxun Huiju Network Technology w wersji 3.7.10 x64 Build202401261655 jest podatne na atak ICMP redirect. Atakujący zdalnie, bez uwierzytelnienia, może manipulować tablicą routingu urządzenia, co umożliwia przekierowanie ruchu sieciowego.

pub. 2024-05-20
9.1
CVSS
CRITICAL
CVE-2025-69515

Podatność w systemie infotainment JXL 9 Inch Car Android Double Din Player (Android v12.0) umożliwia atakującemu wymuszenie akceptacji sfałszowanych sygnałów GPS jako prawidłowych. W rezultacie urządzenie raportuje nieprawidłową lub statyczną lokalizację.

pub. 2026-04-07
8.1
CVSS
HIGH
CVE-2024-29415

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.

pub. 2024-05-27
7.5
CVSS
HIGH
CVE-2019-18242

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause the web server to fail.

pub. 2020-03-24
7.2
CVSS
HIGH
CVE-2026-69246

W bibliotece Guzzle (PHP HTTP client) w wersjach przed 7.15.2 i 8.0.1 istnieje podatność SSRF wynikająca z rozbieżności między tym, jak Guzzle waliduje hosta w URI, a tym, jak libcurl dekoduje i interpretuje ten host. Atakujący mogący kontrolować URI żądania może ominąć mechanizmy kontroli dostępu i skłonić aplikację do połączenia się z hostem, który ta miała wykluczyć.

pub. 2026-08-03
7.2
CVSS
HIGH
CVE-2025-53899

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under certain circumstances to intercept upstream communication which could lead to an escalation of privileges. This issue has been patched in version 9.1.0.

pub. 2025-11-29
6.5
CVSS
MEDIUM
CVE-2022-4847

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

pub. 2022-12-29
6.1
CVSS
MEDIUM
CVE-2023-33198

tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache can possibly be poisoned by a tgstation-server (TGS) restart and reattach. This can result in sending chat messages to one of any of the configured IRC or Discord channels for the instance on enabled chat bots. This lasts until the instance's chat channels are updated in TGS or DreamDaemon is restarted. TGS chat commands are unaffected, custom or otherwise.

pub. 2023-05-30
5.1
CVSS
MEDIUM
CVE-2026-72506

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.

pub. 2026-08-13
5.1
CVSS
MEDIUM
CVE-2026-40118

Konsola UDP dostarczona przez Arcserve zawiera błędnie określony cel w podatności kanału komunikacyjnego. Gdy użytkownik skonfiguruje nazwę hosta serwera aktywacyjnego w podatnym produkcie na fikcyjny adres URL, produkt może niezamiernie komunikować się z fikcyjną domeną, powodując ujawnienie informacji.

pub. 2026-04-16
3.2
CVSS
LOW
CVE-2025-0036

W urządzeniach AMD Versal Adaptive SoC nieprawidłowa konfiguracja SSS podczas operacji kryptograficznych w czasie wykonywania (po rozruchu) może spowodować nieprawidłowy zapis i odczyt danych z nieważnych lokalizacji, a także zwracanie niepoprawnych danych kryptograficznych.

pub. 2025-06-10
Informacje
ID: CWE-941
Typ: Base
Podatności: 11
MITRE CWE ↗
← Słownik CWE