Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2023-33949MEDIUMIn Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email EPSS 0.8%CVE-2024-47295HIGHInsecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary passworEPSS 0.8%CVE-2025-7353CRITICALRockwell Automation ControlLogix® Ethernet Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-25894CRITICALFUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default ConfigurationEPSS 0.8%CVE-2026-47393CRITICALPraisonAI `deploy --type api` emits a Flask server with authentication disabled by defaultEPSS 0.8%CVE-2026-57147CRITICALpraisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgeryEPSS 0.8%CVE-2024-31070CRITICALInitialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century SEPSS 0.8%CVE-2022-41648CRITICALThe HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CEPSS 0.7%CVE-2025-1863CRITICALInsecure default settings for recorder productsEPSS 0.7%CVE-2024-45217HIGHApache Solr: ConfigSets created during a backup restore command are trusted implicitlyEPSS 0.7%CVE-2022-3262HIGHA flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. ThEPSS 0.7%CVE-2025-41438CRITICALConsilium Safety CS5000 Fire Panel Initialization of a Resource with an Insecure DefaultEPSS 0.7%CVE-2026-44109CRITICALOpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action ValidationEPSS 0.7%CVE-2026-33037HIGHWWBN AVideo has predictable default admin credentials in official Docker deployment pathEPSS 0.7%CVE-2021-35535HIGHInsufficient Security Control VulnerabilityEPSS 0.7%CVE-2025-47945CRITICALDonetick Has Weak Default JWT SecretEPSS 0.7%CVE-2024-8383HIGHFirefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does noEPSS 0.6%CVE-2025-59097CRITICALUnauthenticated SOAP API in dormakaba access managerEPSS 0.6%CVE-2025-41245MEDIUMVMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)EPSS 0.6%CVE-2026-55454CRITICALAppsmith: Caddy admin API exposed without authenticationEPSS 0.6%