Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2026-44588CRITICALSiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSSEPSS 0.5%CVE-2025-1960CRITICALCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized coEPSS 0.5%CVE-2026-31957CRITICALHimmelblau unset domain configuration can allow any-tenant authentication at first login for remote deploymentsEPSS 0.5%CVE-2025-22248CRITICAL[pgpool] Unauthenticated access to postgres through pgpoolEPSS 0.5%CVE-2026-46386CRITICALOpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`EPSS 0.5%CVE-2019-25219HIGHAsio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSEPSS 0.5%CVE-2025-69970CRITICALFUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented ouEPSS 0.5%CVE-2026-56285HIGHNitter - Server-Side Request Forgery in /video Media Proxy EndpointEPSS 0.5%CVE-2023-40708MEDIUMImproper Access Control in OPTO 22 SNAP PAC S1EPSS 0.5%CVE-2026-89139HIGHTemporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service hostEPSS 0.5%CVE-2023-28978MEDIUMJunos OS Evolved: Read access to some confidential user information is possibleEPSS 0.5%CVE-2025-24288CRITICALThe Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multEPSS 0.5%CVE-2026-61793MEDIUMNuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameterEPSS 0.5%CVE-2026-62185HIGHArgo CD Helm Chart < 10.0.0 Missing Network Policy RCEEPSS 0.5%CVE-2026-62388HIGHNLTK before 3.10.0 Insecure Default Configuration in pathsec.pyEPSS 0.5%CVE-2026-34742HIGHModel Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on LocalhostEPSS 0.5%CVE-2025-46599MEDIUMCNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations,EPSS 0.5%CVE-2026-28205CRITICALInitialization of a resource with an insecure default in OpenPLC_V3EPSS 0.4%CVE-2026-25499HIGHterraform-provider-proxmox has insecure sudo recommendation in the documentationEPSS 0.4%CVE-2026-62415CRITICALJoomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2EPSS 0.4%