Weaknesses of type CWE-940

60 results

Verificação inadequada da origem de um canal de comunicação

A aplicação aceita dados ou comandos de um canal de comunicação sem verificar adequadamente se a origem é realmente confiável. Isso permite que um atacante se faça passar por um componente legítimo — servidor, cliente, módulo interno — e injete dados maliciosos ou comandos não autorizados.

Example

Um serviço backend recebe requisições em um socket ou fila de mensagens sem validar se o remetente é autenticado; um atacante se conecta à mesma fila e envia comandos administrativos forjados, conseguindo alterar configurações da aplicação.

How to mitigate

Implemente autenticação obrigatória (certificados, tokens, chaves) antes de aceitar qualquer dado do canal; valide a identidade da origem em cada mensagem e rejeite tudo que não puder ser verificado. Use criptografia e assinatura digital para garantir integridade e origem.

CVE-2025-25305HIGHSSL validation for outgoing requests in Home Assistant Core and used libs not correctEPSS 0.3%CVE-2025-23222HIGHAn issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, EPSS 0.2%CVE-2026-40434HIGHAnviz CrossChex Standard Improper Verification of Source of a Communication ChannelEPSS 0.2%CVE-2026-43880MEDIUMWWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From AddressEPSS 0.2%CVE-2026-89178HIGHHowyar|WeenyGenius - Origin Validation ErrorEPSS 0.2%CVE-2026-85085CRITICALThe Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page lEPSS 0.2%CVE-2025-43280MEDIUMThe issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remoEPSS 0.2%CVE-2024-0009MEDIUMPAN-OS: Improper IP Address Verification in GlobalProtect GatewayEPSS 0.2%CVE-2026-73419MEDIUMNextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created themEPSS 0.2%CVE-2026-85125MEDIUMThe Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. ThEPSS 0.2%CVE-2026-22269MEDIUMDell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerabEPSS 0.2%CVE-2025-20365MEDIUMA vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacEPSS 0.2%CVE-2023-7004MEDIUMCVE-2023-7004EPSS 0.2%CVE-2025-9999HIGHImproper validation of payload elementsEPSS 0.2%CVE-2025-0036LOWIn AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause dEPSS 0.1%CVE-2026-44894HIGHNetty's Default QUIC token handler accepts any client-supplied tokenEPSS 0.1%CVE-2025-62439LOWAn Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4,EPSS 0.1%CVE-2026-44698HIGHHome Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionEPSS 0.1%CVE-2025-42978LOWInsufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Application Server JavaEPSS 0.1%CVE-2026-45353CRITICALelecterm: Local code through electerm's single-instance socketEPSS 0.1%