Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2023-48733MEDIUMAn insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure BootEPSS 0.3%CVE-2021-33130MEDIUMInsecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated useEPSS 0.3%CVE-2025-43015HIGHIn JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfacesEPSS 0.3%CVE-2024-5801MEDIUMIP Forwarding enabled in B&R Automation RuntimeEPSS 0.3%CVE-2025-2442MEDIUMCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unauthorized access whicEPSS 0.2%CVE-2026-41931MEDIUMVvveb < 1.0.8.2 Information Disclosure via Debug Exception HandlerEPSS 0.2%CVE-2025-43797MEDIUMIn Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through EPSS 0.2%CVE-2026-77348HIGHWallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`EPSS 0.2%CVE-2026-65881HIGHJoomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1EPSS 0.2%CVE-2026-9680MEDIUMMCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-serverEPSS 0.2%CVE-2022-24287HIGHA vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 VEPSS 0.2%CVE-2026-75062CRITICALEval Injection in google/langfun via default lf.query protocolEPSS 0.2%CVE-2026-54800MEDIUMA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < VEPSS 0.2%CVE-2026-40994HIGHWss4jSecurityInterceptor disables WS-I BSP validation by defaultEPSS 0.2%CVE-2026-33072HIGHFileRise: Default Encryption Key Enables Token Forgery and Config DecryptionEPSS 0.2%CVE-2025-2441MEDIUMCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicEPSS 0.2%CVE-2025-62802MEDIUMDNN CKEditor Provider allows unauthenticated upload out-of-the-boxEPSS 0.2%CVE-2026-20265MEDIUMInsecure Default Domain Allowlist in Splunk AI ToolkitEPSS 0.2%CVE-2024-8313HIGHDefault or Guessable SNMP community names in B&R APROLEPSS 0.2%CVE-2026-43581CRITICALOpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay BindingEPSS 0.2%