Fallos del tipo CWE-16

62 resultados

Configuração Incorreta

Fraqueza genérica que cobre falhas na configuração de software, sistemas ou aplicações que deixam brechas de segurança exploráveis. Pode envolver permissões inadequadas, padrões mantidos, serviços desnecessários ativos ou parâmetros inseguros que o desenvolvedor ou administrador não ajustou corretamente.

Ejemplo

Um servidor web em produção rodando com debug ativado, expondo stack traces e informações internas; ou um banco de dados com credenciais padrão nunca alteradas; ou um aplicativo que deixa arquivos de configuração com senhas em texto plano no repositório versionado.

Cómo mitigar

Aplique checklist de hardening (desative serviços e recursos desnecessários, altere credenciais padrão, remova modo debug em produção), use Infrastructure as Code com validação de segurança, implemente auditoria de configurações e siga guias de segurança da comunidade (OWASP Top 10, CIS Benchmarks) para cada tecnologia em uso.

CVE-2019-1585MEDIUMCisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Privilege Escalation VulnerabilityEPSS 0.4%CVE-2020-16247MEDIUMPhilips Clinical Collaboration Platform ConfigurationEPSS 0.4%CVE-2019-18579HIGHSettings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for thEPSS 0.3%CVE-2018-0275A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to accessEPSS 0.3%CVE-2020-8351HIGHA privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user toEPSS 0.3%CVE-2022-36423HIGHIncorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.EPSS 0.3%CVE-2022-28762HIGHDebugging port misconfiguration in Zoom Apps in the Zoom Client for Meetings for macOSEPSS 0.3%CVE-2023-43088HIGH Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the systemEPSS 0.3%CVE-2024-42031HIGHAccess permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect servicEPSS 0.3%CVE-2023-39392Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciouEPSS 0.2%CVE-2018-11922HIGHConfigurations in Android BuildEPSS 0.2%CVE-2021-21532MEDIUMDell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploitedEPSS 0.2%CVE-2024-47294MEDIUMAccess permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may EPSS 0.2%CVE-2017-12306A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade paEPSS 0.2%CVE-2026-4433LOWAn SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnEPSS 0.2%CVE-2023-52719HIGHPrivilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.2%CVE-2025-12221LOWCSRF Token not Properly ImplementedEPSS 0.2%CVE-2022-33233HIGHConfiguration weakness in modemEPSS 0.1%CVE-2026-56586LOWHCL IEM was affected with X-Content-Type-Options Header MissingEPSS 0.1%CVE-2024-47291MEDIUMPermission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availabEPSS 0.1%