Weaknesses of type CWE-923

74 results

Restrição inadequada do canal de comunicação aos pontos finais pretendidos

A aplicação falha em validar ou restringir adequadamente para quem está enviando ou recebendo dados, permitindo que comunicações cheguem a endpoints não autorizados. Isso ocorre quando não há verificação suficiente de origem, destino ou identidade das partes na comunicação, criando brechas para interceptação, redirecionamento ou acesso por terceiros.

Example

Um serviço de microserviços que se comunica via gRPC sem validar certificados TLS, permitindo que um atacante na mesma rede se passe por outro serviço legítimo e intercepte requisições sensíveis. Ou uma API que não valida o referer/origin e permite requisições de domínios arbitrários, viabilizando CSRF ou roubo de dados.

How to mitigate

Implemente validação explícita de origem/identidade (certificados mTLS, tokens assinados, IP whitelisting conforme contexto); use canais criptografados e autenticados (TLS, HTTPS obrigatório); valide headers como Origin, Referer e implemente CORS restritivo; autentique ambos os lados da comunicação, nunca confiando implicitamente na rede.

CVE-2022-43916MEDIUMIBM App Connect Enterprise Certified Container improper communications restrictionEPSS 0.3%CVE-2025-61939HIGHColumbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended EndpointsEPSS 0.3%CVE-2023-25518HIGH NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with pEPSS 0.3%CVE-2024-39271LOWImproper restriction of communication channel to intended endpoints in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software beforeEPSS 0.3%CVE-2026-34205CRITICALHome Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network ModeEPSS 0.3%CVE-2025-23178HIGHRibbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended EndpointsEPSS 0.3%CVE-2026-18655HIGHBroker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt InjectionEPSS 0.3%CVE-2026-59841MEDIUMA improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 maEPSS 0.2%CVE-2024-22315MEDIUMIBM Fusion improper communication restrictionEPSS 0.2%CVE-2024-36252MEDIUMImproper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If EPSS 0.2%CVE-2026-90461MEDIUMOpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) BEPSS 0.2%CVE-2026-22715MEDIUMVMware Workstation/Fusion NAT vulnerabilityEPSS 0.2%CVE-2026-22726MEDIUMRoute Services Firewall BypassEPSS 0.2%CVE-2026-81871MEDIUMOpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinningEPSS 0.2%CVE-2025-36180MEDIUMInadequate Pod Communication Restrictions, affects watsonx.dataEPSS 0.2%CVE-2025-58742HIGHInsufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirector CaptureEPSS 0.2%CVE-2022-2835MEDIUMA flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by theEPSS 0.2%CVE-2026-91166MEDIUMWarpgate: Web SSH stores a jump host's key against the target's address, so it validates as the targetEPSS 0.2%CVE-2025-36145MEDIUMMultiple Vulnerabilities in watsonx.dataEPSS 0.2%CVE-2022-38125LOWFTP Agent forwards traffic on inactive ports to LinkManagerEPSS 0.2%