Weaknesses of type CWE-16

62 results

Configuração Incorreta do Sistema

É quando um software, servidor ou aplicação é instalado ou mantido com configurações padrão, inseguras ou inadequadas para o ambiente. O atacante explora essas falhas (como senhas padrão, módulos desnecessários ativados, ou permissões muito abertas) para ganhar acesso ou contornar proteções.

Example

Um banco de dados PostgreSQL rodando com usuário 'postgres' e senha padrão, exposto na rede; ou um servidor web com diretório de listagem de arquivos ativo, expondo arquivos sensíveis ao navegador.

How to mitigate

Aplique hardening seguindo guias de configuração segura (CIS Benchmarks, documentação oficial); desative serviços e módulos desnecessários; altere credenciais padrão imediatamente; use ferramentas de varredura de configuração (Nessus, OpenSCAP) para auditoria contínua.

CVE-2019-1585MEDIUMCisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Privilege Escalation VulnerabilityEPSS 0.4%CVE-2020-16247MEDIUMPhilips Clinical Collaboration Platform ConfigurationEPSS 0.4%CVE-2019-18579HIGHSettings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for thEPSS 0.3%CVE-2018-0275A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to accessEPSS 0.3%CVE-2020-8351HIGHA privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user toEPSS 0.3%CVE-2022-36423HIGHIncorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.EPSS 0.3%CVE-2022-28762HIGHDebugging port misconfiguration in Zoom Apps in the Zoom Client for Meetings for macOSEPSS 0.3%CVE-2023-43088HIGH Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the systemEPSS 0.3%CVE-2024-42031HIGHAccess permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect servicEPSS 0.3%CVE-2023-39392Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciouEPSS 0.2%CVE-2018-11922HIGHConfigurations in Android BuildEPSS 0.2%CVE-2021-21532MEDIUMDell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploitedEPSS 0.2%CVE-2024-47294MEDIUMAccess permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may EPSS 0.2%CVE-2017-12306A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade paEPSS 0.2%CVE-2023-52719HIGHPrivilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.2%CVE-2026-4433LOWAn SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnEPSS 0.2%CVE-2025-12221LOWCSRF Token not Properly ImplementedEPSS 0.2%CVE-2022-33233HIGHConfiguration weakness in modemEPSS 0.1%CVE-2026-56586LOWHCL IEM was affected with X-Content-Type-Options Header MissingEPSS 0.1%CVE-2024-47291MEDIUMPermission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availabEPSS 0.1%