Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2020-11915MEDIUMAn issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to tEPSS 0.6%CVE-2026-14474HIGHSssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalationEPSS 0.6%CVE-2026-2617MEDIUMBeetel 777VR1 Telnet Service/SSH Service insecure default initialization of resourceEPSS 0.6%CVE-2020-11917MEDIUMAn issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers EPSS 0.6%CVE-2024-51758LOWExported files stored in default (`public`) filesystem if not reconfigured in filamentEPSS 0.6%CVE-2026-60024CRITICALJoomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0EPSS 0.5%CVE-2026-54067CRITICALSiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()EPSS 0.5%CVE-2026-39920CRITICALBridgeHead FileStore < 24A Apache Axis2 Default Credentials RCEEPSS 0.5%CVE-2024-0387MEDIUMEDS-4000/G4000 Series IP Forwarding VulnerabilityEPSS 0.5%CVE-2025-59321CRITICALCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This EPSS 0.5%CVE-2023-5368msdosfs data disclosureEPSS 0.5%CVE-2025-13357HIGHVault Terraform Provider Applied Incorrect Defaults for LDAP Auth MethodEPSS 0.5%CVE-2024-26267MEDIUMIn Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 befEPSS 0.5%CVE-2025-62877CRITICALHarvest may expose OS default ssh login password via SUSE Virtualization Interactive InstallerEPSS 0.5%CVE-2024-25610CRITICALIn Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 befoEPSS 0.5%CVE-2025-66416HIGHDNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on LocalhostEPSS 0.5%CVE-2025-66414HIGHDNS Rebinding Protection Disabled by Default in Model Context Protocol TypeScript SDK for Servers Running on LocalhostEPSS 0.5%CVE-2024-41995HIGHInitialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability iEPSS 0.5%CVE-2026-44588CRITICALSiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSSEPSS 0.5%CVE-2026-44670CRITICALSiYuan: Stored XSS via Attribute View name to Electron renderer RCE in SiYuanEPSS 0.5%