Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2025-64781MEDIUMIn GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External pEPSS 0.2%CVE-2026-9039HIGHInitialization of a resource with an insecure default in XCharge C6EPSS 0.2%CVE-2026-46430MEDIUMAlgernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOSEPSS 0.2%CVE-2025-27809MEDIUMMbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unlEPSS 0.2%CVE-2026-54359HIGHMISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by defaultEPSS 0.2%CVE-2025-14758MEDIUMInitialization of a Resource with an Insecure Default in YAOOKEPSS 0.2%CVE-2025-52622MEDIUMHCL BigFix SaaS Remediate is affected by a security vulnerabilityEPSS 0.2%CVE-2025-31974LOWHCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-OnlyEPSS 0.2%CVE-2026-54907MEDIUMCaddy Proxy Manager: Registrations enabled by default allows creating users with "user" permissionEPSS 0.2%CVE-2025-5591HIGHStored Cross-site Scripting (XSS) in Kentico Xperience 13EPSS 0.2%CVE-2024-22388MEDIUMInsecure Default Initialization of Resource in HID GlobalEPSS 0.2%CVE-2024-30124MEDIUMHCL Sametime is impacted by insecure servicesEPSS 0.2%CVE-2023-3485LOWInsecure Default Authorization in Temporal ServerEPSS 0.2%CVE-2024-48122MEDIUMInsecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileges to escalate to roEPSS 0.2%CVE-2025-27443LOWZoom Workplace Apps for Windows - Insecure Default Variable InitializationEPSS 0.2%CVE-2026-46517HIGHLMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-outEPSS 0.2%CVE-2026-24197MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default iniEPSS 0.2%CVE-2022-48432MEDIUMIn JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.EPSS 0.2%CVE-2026-55708LOWPrivacy/configuration issue when adding local data in views through 'unbound-control'EPSS 0.1%CVE-2026-75926CRITICALHugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process GrantEPSS 0.1%