Weaknesses of type CWE-16

62 results

Configuração Incorreta do Sistema

É quando um software, servidor ou aplicação é instalado ou mantido com configurações padrão, inseguras ou inadequadas para o ambiente. O atacante explora essas falhas (como senhas padrão, módulos desnecessários ativados, ou permissões muito abertas) para ganhar acesso ou contornar proteções.

Example

Um banco de dados PostgreSQL rodando com usuário 'postgres' e senha padrão, exposto na rede; ou um servidor web com diretório de listagem de arquivos ativo, expondo arquivos sensíveis ao navegador.

How to mitigate

Aplique hardening seguindo guias de configuração segura (CIS Benchmarks, documentação oficial); desative serviços e módulos desnecessários; altere credenciais padrão imediatamente; use ferramentas de varredura de configuração (Nessus, OpenSCAP) para auditoria contínua.

CVE-2024-46909CRITICALWhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution VulnerabilityEPSS 49.2%CVE-2017-6639A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unautEPSS 35.4%CVE-2019-15993HIGHCisco Small Business Switches Information Disclosure VulnerabilityEPSS 10.3%CVE-2018-0262A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or senEPSS 4.1%CVE-2018-15386Cisco Digital Network Architecture Center Unauthenticated Access VulnerabilityEPSS 3.4%CVE-2017-12249A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remoteEPSS 3.1%CVE-2019-3939Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the wEPSS 2.8%CVE-2019-1742HIGHCisco IOS XE Software Information Disclosure VulnerabilityEPSS 2.2%CVE-2018-15448MEDIUMCisco Registered Envelope Service Information Disclosure VulnerabilityEPSS 2.2%CVE-2020-2041HIGHPAN-OS: Management web interface denial-of-service (DoS)EPSS 2.1%CVE-2019-1868MEDIUMCisco Webex Meetings Server Information Disclosure VulnerabilityEPSS 2.1%CVE-2021-20032SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potEPSS 2.0%CVE-2019-19001MEDIUMeSOMS X-FrameOptionEPSS 1.5%CVE-2019-16760MEDIUMCargo prior to Rust 1.26.0 may download the wrong dependencyEPSS 1.3%CVE-2020-1769LOWAutocomplete in the form login screensEPSS 1.3%CVE-2022-29095HIGHDell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain aEPSS 1.1%CVE-2021-31381MEDIUMSRC Series: A remote attacker sending a specially crafted query may cause the web server to delete filesEPSS 1.1%CVE-2021-31380MEDIUMSRC Series: A remote attacker sending a specially crafted query may cause the web server to disclose sensitive informationEPSS 1.1%CVE-2020-3484MEDIUMCisco Vision Dynamic Signage Director Directory Traversal Information Disclosure VulnerabilityEPSS 1.1%CVE-2019-19000MEDIUMeSOMS Cachecontrol (Pragma) HTTP HeaderEPSS 1.1%