Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2020-13927CRITICALThe previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riEPSS 99.8%KEVCVE-2023-27524HIGHApache Superset: Session validation vulnerability when using provided default SECRET_KEYEPSS 97.4%KEVCVE-2022-24706CRITICALRemote Code Execution Vulnerability in PackagingEPSS 92.5%KEVCVE-2026-44338HIGHPraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow executionEPSS 28.6%CVE-2026-66066CRITICALAction Pack: Possible arbitrary file read and remote code execution in Active Storage variant processingEPSS 27.9%CVE-2026-41679CRITICALPaperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization BypassEPSS 18.9%CVE-2025-48927MEDIUMThe TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploitEPSS 11.1%KEVCVE-2021-41192HIGHInsecure default configurationEPSS 8.1%CVE-2024-32114HIGHApache ActiveMQ: Jolokia and REST API were not secured with default configurationEPSS 7.1%CVE-2026-67208CRITICALJuggle 1.6.0 Unauthenticated RCE via Exposed H2 ConsoleEPSS 5.3%CVE-2026-47668CRITICALDbGate: Unauthenticated Remote Code Execution via JSON Script RunnerEPSS 3.9%CVE-2026-44825HIGHApache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure usersEPSS 2.9%CVE-2026-54066HIGHSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)EPSS 2.4%CVE-2024-22207MEDIUMDefault swagger-ui configuration exposes all files in the moduleEPSS 2.3%CVE-2023-6448CRITICALUnitronics VisiLogic uses a default administrative passwordEPSS 2.1%KEVCVE-2026-52824CRITICALKimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account TakeoverEPSS 2.1%CVE-2019-19340HIGHA flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-EPSS 1.5%CVE-2023-45312HIGHIn the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly securEPSS 1.5%CVE-2024-2912CRITICALInsecure Deserialization Leading to RCE in bentoml/bentomlEPSS 1.5%CVE-2022-42467MEDIUMh2 webconsole (available only in prototype mode) should nevertheless be disabled by default.EPSS 1.3%