Weaknesses of type CWE-923

74 results

Restrição inadequada do canal de comunicação aos pontos finais pretendidos

A aplicação falha em validar ou restringir adequadamente para quem está enviando ou recebendo dados, permitindo que comunicações cheguem a endpoints não autorizados. Isso ocorre quando não há verificação suficiente de origem, destino ou identidade das partes na comunicação, criando brechas para interceptação, redirecionamento ou acesso por terceiros.

Example

Um serviço de microserviços que se comunica via gRPC sem validar certificados TLS, permitindo que um atacante na mesma rede se passe por outro serviço legítimo e intercepte requisições sensíveis. Ou uma API que não valida o referer/origin e permite requisições de domínios arbitrários, viabilizando CSRF ou roubo de dados.

How to mitigate

Implemente validação explícita de origem/identidade (certificados mTLS, tokens assinados, IP whitelisting conforme contexto); use canais criptografados e autenticados (TLS, HTTPS obrigatório); valide headers como Origin, Referer e implemente CORS restritivo; autentique ambos os lados da comunicação, nunca confiando implicitamente na rede.

CVE-2026-23904HIGHApache Kyuubi: Unrestricted access via Kyuubi engine-ui proxyEPSS 0.5%CVE-2024-26013HIGHA improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.EPSS 0.5%CVE-2026-78501HIGHMicrosoft 365 Copilot Business Chat Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-31144MEDIUMQuick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, aEPSS 0.5%CVE-2024-26131HIGHElement Android Intent RedirectionEPSS 0.5%CVE-2025-20261HIGHCisco Integrated Management Controller Privilege Escalation VulnerabilityEPSS 0.5%CVE-2026-62836HIGHAzure SQL Managed Instance Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-29108MEDIUMIP filter vulnerability in ABAP Platform and SAP Web Dispatcher EPSS 0.4%CVE-2025-22251LOWAn improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 alEPSS 0.4%CVE-2023-44195MEDIUMJunos OS Evolved: Packets which are not destined to the router can reach the REEPSS 0.4%CVE-2022-2837MEDIUMA flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod thEPSS 0.4%CVE-2023-28971HIGHParagon Active Assurance: Enabling the timescaledb enables IP forwardingEPSS 0.4%CVE-2026-63226MEDIUMPrinters and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing toEPSS 0.4%CVE-2026-33803MEDIUMJunos OS Evolved: A port which has been inadvertently exposed can be reached by an attackerEPSS 0.4%CVE-2024-39537MEDIUMJunos OS Evolved: ACX7000 Series: Ports which have been inadvertently exposed can be reached over the networkEPSS 0.3%CVE-2025-49734HIGHPowerShell Direct Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-57028MEDIUMJunos OS Evolved: A port which has been inadvertently exposed can be reached by an attackerEPSS 0.3%CVE-2026-87734HIGHAn issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.EPSS 0.3%CVE-2025-29986HIGHDell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulneraEPSS 0.3%CVE-2025-62843LOWQuRouterEPSS 0.3%