Fallos del tipo CWE-16

62 resultados

Configuração Incorreta

Fraqueza genérica que cobre falhas na configuração de software, sistemas ou aplicações que deixam brechas de segurança exploráveis. Pode envolver permissões inadequadas, padrões mantidos, serviços desnecessários ativos ou parâmetros inseguros que o desenvolvedor ou administrador não ajustou corretamente.

Ejemplo

Um servidor web em produção rodando com debug ativado, expondo stack traces e informações internas; ou um banco de dados com credenciais padrão nunca alteradas; ou um aplicativo que deixa arquivos de configuração com senhas em texto plano no repositório versionado.

Cómo mitigar

Aplique checklist de hardening (desative serviços e recursos desnecessários, altere credenciais padrão, remova modo debug em produção), use Infrastructure as Code com validação de segurança, implemente auditoria de configurações e siga guias de segurança da comunidade (OWASP Top 10, CIS Benchmarks) para cada tecnologia em uso.

CVE-2024-46909CRITICALWhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution VulnerabilityEPSS 49.2%CVE-2017-6639A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unautEPSS 35.4%CVE-2019-15993HIGHCisco Small Business Switches Information Disclosure VulnerabilityEPSS 10.3%CVE-2018-0262A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or senEPSS 4.1%CVE-2018-15386Cisco Digital Network Architecture Center Unauthenticated Access VulnerabilityEPSS 3.4%CVE-2017-12249A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remoteEPSS 3.1%CVE-2019-3939Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the wEPSS 2.8%CVE-2019-1742HIGHCisco IOS XE Software Information Disclosure VulnerabilityEPSS 2.2%CVE-2018-15448MEDIUMCisco Registered Envelope Service Information Disclosure VulnerabilityEPSS 2.2%CVE-2020-2041HIGHPAN-OS: Management web interface denial-of-service (DoS)EPSS 2.1%CVE-2019-1868MEDIUMCisco Webex Meetings Server Information Disclosure VulnerabilityEPSS 2.1%CVE-2021-20032SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potEPSS 2.0%CVE-2019-19001MEDIUMeSOMS X-FrameOptionEPSS 1.5%CVE-2019-16760MEDIUMCargo prior to Rust 1.26.0 may download the wrong dependencyEPSS 1.3%CVE-2020-1769LOWAutocomplete in the form login screensEPSS 1.3%CVE-2022-29095HIGHDell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain aEPSS 1.1%CVE-2021-31381MEDIUMSRC Series: A remote attacker sending a specially crafted query may cause the web server to delete filesEPSS 1.1%CVE-2021-31380MEDIUMSRC Series: A remote attacker sending a specially crafted query may cause the web server to disclose sensitive informationEPSS 1.1%CVE-2020-3484MEDIUMCisco Vision Dynamic Signage Director Directory Traversal Information Disclosure VulnerabilityEPSS 1.1%CVE-2019-19000MEDIUMeSOMS Cachecontrol (Pragma) HTTP HeaderEPSS 1.1%