Fallos del tipo CWE-1188

214 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2025-59044MEDIUMHimmelblau vulnerable to GID collision via group name-derived mapping (privilege escalation)EPSS 0.1%CVE-2026-36612MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-second lockout after 10 aEPSS 0.1%CVE-2024-9949MEDIUMDenial of Service in Forescout SecureConnectorEPSS 0.1%CVE-2026-36616MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS teEPSS 0.1%CVE-2024-34063LOWDegraded secret zeroization capabilities in vodozemacEPSS 0.1%CVE-2025-48621HIGHIn DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local EPSS 0.1%CVE-2025-32330MEDIUMIn generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecuEPSS 0.1%CVE-2026-27662HIGHAffected devices do not properly restrict access to the web browser via the Control Panel when no corresponding security mechanisms are in pEPSS 0.1%CVE-2022-20466MEDIUMIn applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary dEPSS 0.1%CVE-2026-33921MEDIUMNpcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0EPSS 0.1%CVE-2024-34734HIGHIn onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen EPSS 0.1%CVE-2025-48629HIGHIn findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to anEPSS 0.1%CVE-2026-0134MEDIUMIn PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This EPSS 0.1%CVE-2026-86246Apache Tomcat Native: Insecure OpenSSL options enabledEPSS