Weaknesses of type CWE-16

62 results

Configuração Incorreta do Sistema

É quando um software, servidor ou aplicação é instalado ou mantido com configurações padrão, inseguras ou inadequadas para o ambiente. O atacante explora essas falhas (como senhas padrão, módulos desnecessários ativados, ou permissões muito abertas) para ganhar acesso ou contornar proteções.

Example

Um banco de dados PostgreSQL rodando com usuário 'postgres' e senha padrão, exposto na rede; ou um servidor web com diretório de listagem de arquivos ativo, expondo arquivos sensíveis ao navegador.

How to mitigate

Aplique hardening seguindo guias de configuração segura (CIS Benchmarks, documentação oficial); desative serviços e módulos desnecessários; altere credenciais padrão imediatamente; use ferramentas de varredura de configuração (Nessus, OpenSCAP) para auditoria contínua.

CVE-2019-19089MEDIUMeSOMS: X-Content-Type-Options Header MissingEPSS 1.1%CVE-2022-22183HIGHJunos OS Evolved: A remote attacker may cause a CPU Denial of Service by sending genuine traffic to a device on a specific IPv4 port.EPSS 1.0%CVE-2021-35233MEDIUMHTTP TRACK & TRACE Methods EnabledEPSS 1.0%CVE-2022-43516MEDIUMZabbix Agent installer adds “allow all TCP any any” firewall ruleEPSS 0.9%CVE-2021-22957A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor EPSS 0.9%CVE-2022-37397HIGHThe software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active DirectoryEPSS 0.9%CVE-2019-19092LOWABB eSOMS: Viewstate without MAC SignatureEPSS 0.8%CVE-2019-19002MEDIUMABB eSOMS X-XSS-Protection not enabledEPSS 0.8%CVE-2019-19003MEDIUMABB eSOMS: HTTPOnly flag not setEPSS 0.8%CVE-2019-19091MEDIUMABB eSOMS: HTTP response information leakageEPSS 0.8%CVE-2023-33105HIGHConfiguration Issue in WLAN Host and FirmwareEPSS 0.8%CVE-2018-0263A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal devicEPSS 0.7%CVE-2019-19097MEDIUMABB eSOMS: SSL medium strength Cipher SuitesEPSS 0.7%CVE-2021-0222HIGHJunos OS: Upon receipt of certain protocol packets with invalid payloads a self-propagating Denial of Service may occur.EPSS 0.6%CVE-2020-8353MEDIUMPrior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) featureEPSS 0.6%CVE-2024-32991HIGHPermission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availabEPSS 0.5%CVE-2019-19090LOWABB eSOMS: Secure Flag not setEPSS 0.5%CVE-2019-1829MEDIUMCisco Aironet Series Access Points Command Injection VulnerabilityEPSS 0.4%CVE-2023-39385Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unaEPSS 0.4%CVE-2025-20151MEDIUMCisco IOS and IOS XE Software SNMPv3 Configuration Restriction VulnerabilityEPSS 0.4%