Falhas do tipo CWE-300

55 resultados

Ataque Homem no Meio (Man-in-the-Middle)

Fraqueza que permite a um atacante interceptar, ler ou modificar comunicações entre dois pontos (cliente-servidor, serviço-serviço) sem que as partes saibam. Ocorre quando faltam mecanismos de autenticação ou criptografia adequados, deixando a conexão exposta a espionagem e manipulação.

Exemplo

Um app móvel se conecta a um servidor via HTTP simples para sincronizar dados de usuário. Um atacante na mesma rede Wi-Fi pode interceptar as requisições com Wireshark ou ferramentas similares, capturando senhas, tokens ou injetando comandos maliciosos nas respostas antes delas chegarem ao app.

Como mitigar

Use HTTPS/TLS em todas as conexões sensíveis, valide certificados do servidor (nunca ignore avisos de certificado inválido), implemente pinning de certificado em apps móveis críticos e, quando possível, adicione autenticação mútua (cliente valida servidor e vice-versa). Em APIs internas, use VPN ou mTLS.

CVE-2021-21953HIGHAn authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. AEPSS 1.0%CVE-2017-9941A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle EPSS 0.9%CVE-2017-6870A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol imEPSS 0.9%CVE-2018-13298MEDIUMChannel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attacEPSS 0.9%CVE-2023-7008MEDIUMSystemd-resolved: unsigned name response in signed zone is not refused when dnssec=yesEPSS 0.8%CVE-2019-14899HIGHA vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent userEPSS 0.8%CVE-2020-11024MEDIUMMan-in-the-middle attack in Moonlight iOS/tvOSEPSS 0.8%CVE-2021-31386MEDIUMJunos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks.EPSS 0.7%CVE-2017-6052A Man-in-the-Middle issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. Communication channel endpoints are not verifieEPSS 0.6%CVE-2019-0054MEDIUMJunos OS: SRX Series: An attacker may be able to perform Man-in-the-Middle (MitM) attacks during app-id signature updates.EPSS 0.6%CVE-2022-22156MEDIUMJunos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URLEPSS 0.5%CVE-2024-32049HIGHBIG-IP Next Central Manager vulnerabilityEPSS 0.5%CVE-2023-2310MEDIUMChannel Accessible by Non-EndpointEPSS 0.5%CVE-2025-31214HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged netEPSS 0.5%CVE-2023-32634HIGHAn authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta. An attEPSS 0.4%CVE-2019-8282Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language paEPSS 0.4%CVE-2024-50565LOWA improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.EPSS 0.4%CVE-2024-50568MEDIUMA channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and beforeEPSS 0.4%CVE-2024-31206HIGHUse of Unencrypted HTTP Request in dectalk-ttsEPSS 0.3%CVE-2023-38272MEDIUMIBM Cloud Pak System information disclosureEPSS 0.3%