Fallos del tipo CWE-923

68 resultados

Restrição inadequada de canal de comunicação para endpoints pretendidos

Ocorre quando a aplicação não valida corretamente se está se comunicando com o endpoint correto, permitindo que um atacante intercepte, redirecione ou substitua a comunicação. O código assume que está falando com o servidor legítimo sem verificar identidade, certificados ou origem, criando janelas para man-in-the-middle ou redirecionamento malicioso.

Ejemplo

Uma app mobile conecta a um servidor via HTTP sem validar certificado SSL/TLS, ou aceita qualquer certificado autoassinado. Um atacante na mesma rede WiFi intercepta a conexão e serve credenciais falsas; a app não detecta porque não verificou a autenticidade do servidor.

Cómo mitigar

Sempre validar certificados SSL/TLS (fixar certificado público se possível), usar HTTPS obrigatório, implementar verificação de hostname, e em APIs internas usar autenticação mútua (mTLS). Nunca confiar em claims do servidor sem validação criptográfica.

CVE-2024-26131HIGHElement Android Intent RedirectionEPSS 0.5%CVE-2025-48807MEDIUMWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-29108MEDIUMIP filter vulnerability in ABAP Platform and SAP Web Dispatcher EPSS 0.4%CVE-2025-20261HIGHCisco Integrated Management Controller Privilege Escalation VulnerabilityEPSS 0.4%CVE-2023-44195MEDIUMJunos OS Evolved: Packets which are not destined to the router can reach the REEPSS 0.4%CVE-2022-2837MEDIUMA flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod thEPSS 0.4%CVE-2023-28971HIGHParagon Active Assurance: Enabling the timescaledb enables IP forwardingEPSS 0.4%CVE-2025-22251LOWAn improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 alEPSS 0.3%CVE-2024-39537MEDIUMJunos OS Evolved: ACX7000 Series: Ports which have been inadvertently exposed can be reached over the networkEPSS 0.3%CVE-2025-49734HIGHPowerShell Direct Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-62843LOWQuRouterEPSS 0.3%CVE-2025-29986HIGHDell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulneraEPSS 0.3%CVE-2022-43916MEDIUMIBM App Connect Enterprise Certified Container improper communications restrictionEPSS 0.3%CVE-2023-25518HIGH NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with pEPSS 0.3%CVE-2026-33803MEDIUMJunos OS Evolved: A port which has been inadvertently exposed can be reached by an attackerEPSS 0.3%CVE-2026-34205CRITICALHome Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network ModeEPSS 0.3%CVE-2025-23178HIGHRibbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended EndpointsEPSS 0.3%CVE-2026-18655HIGHBroker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt InjectionEPSS 0.3%CVE-2024-39271LOWImproper restriction of communication channel to intended endpoints in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software beforeEPSS 0.3%CVE-2025-61939HIGHColumbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended EndpointsEPSS 0.2%