Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2026-6043HIGHInsecure Default Configuration in P4 ServerEPSS 1.3%CVE-2025-59090CRITICALUnauthenticated SOAP API in dormakaba Kaba exos 9300EPSS 1.2%CVE-2022-31806CRITICALInsecure default settings in CODESYS Runtime Toolkit 32 bit full and CODESYS PLCWinNTEPSS 1.2%CVE-2026-28775CRITICALUnauthenticated RCE via SNMP Default Writable Community StringEPSS 1.2%CVE-2023-31101Apache InLong: Users who joined later can see the data of deleted usersEPSS 1.1%CVE-2026-87827CRITICALKGUARD DVR unauthenticated remote command execution vulnerabilityEPSS 1.1%CVE-2017-12736HIGHAfter initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This EPSS 1.1%CVE-2025-2129MEDIUMMage AI insecure default initialization of resourceEPSS 1.0%CVE-2024-50390HIGHQHoraEPSS 1.0%CVE-2026-26122MEDIUMMicrosoft ACI Confidential Containers Information Disclosure VulnerabilityEPSS 1.0%CVE-2021-3586A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accesEPSS 1.0%CVE-2024-0001CRITICALA condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowingEPSS 0.9%CVE-2026-50519MEDIUMMicrosoft Visual Studio Code CoPilot Chat Security Feature Bypass VulnerabilityEPSS 0.9%CVE-2024-28815CRITICALA vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4 through 8.6 could allow access to sensitive iEPSS 0.9%CVE-2026-57127CRITICALpraisonai: recipe serve auth middleware silently disables itself when no secret is setEPSS 0.9%CVE-2022-4224HIGHCODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3EPSS 0.9%CVE-2022-38745HIGHApache OpenOffice: Empty entry in Java class pathEPSS 0.9%CVE-2022-32480MEDIUMDell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initializatEPSS 0.9%CVE-2022-1278A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.EPSS 0.9%CVE-2026-41432HIGHNew API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota FraudEPSS 0.9%