Fallos del tipo CWE-923

74 resultados

Restrição inadequada de canal de comunicação para endpoints pretendidos

Ocorre quando a aplicação não valida corretamente se está se comunicando com o endpoint correto, permitindo que um atacante intercepte, redirecione ou substitua a comunicação. O código assume que está falando com o servidor legítimo sem verificar identidade, certificados ou origem, criando janelas para man-in-the-middle ou redirecionamento malicioso.

Ejemplo

Uma app mobile conecta a um servidor via HTTP sem validar certificado SSL/TLS, ou aceita qualquer certificado autoassinado. Um atacante na mesma rede WiFi intercepta a conexão e serve credenciais falsas; a app não detecta porque não verificou a autenticidade do servidor.

Cómo mitigar

Sempre validar certificados SSL/TLS (fixar certificado público se possível), usar HTTPS obrigatório, implementar verificação de hostname, e em APIs internas usar autenticação mútua (mTLS). Nunca confiar em claims do servidor sem validação criptográfica.

CVE-2022-43916MEDIUMIBM App Connect Enterprise Certified Container improper communications restrictionEPSS 0.3%CVE-2025-61939HIGHColumbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended EndpointsEPSS 0.3%CVE-2023-25518HIGH NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with pEPSS 0.3%CVE-2024-39271LOWImproper restriction of communication channel to intended endpoints in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software beforeEPSS 0.3%CVE-2026-34205CRITICALHome Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network ModeEPSS 0.3%CVE-2025-23178HIGHRibbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended EndpointsEPSS 0.3%CVE-2026-18655HIGHBroker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt InjectionEPSS 0.3%CVE-2026-59841MEDIUMA improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 maEPSS 0.2%CVE-2024-22315MEDIUMIBM Fusion improper communication restrictionEPSS 0.2%CVE-2024-36252MEDIUMImproper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If EPSS 0.2%CVE-2026-90461MEDIUMOpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) BEPSS 0.2%CVE-2026-22715MEDIUMVMware Workstation/Fusion NAT vulnerabilityEPSS 0.2%CVE-2026-22726MEDIUMRoute Services Firewall BypassEPSS 0.2%CVE-2026-81871MEDIUMOpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinningEPSS 0.2%CVE-2025-36180MEDIUMInadequate Pod Communication Restrictions, affects watsonx.dataEPSS 0.2%CVE-2025-58742HIGHInsufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirector CaptureEPSS 0.2%CVE-2022-2835MEDIUMA flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by theEPSS 0.2%CVE-2025-36145MEDIUMMultiple Vulnerabilities in watsonx.dataEPSS 0.2%CVE-2022-38125LOWFTP Agent forwards traffic on inactive ports to LinkManagerEPSS 0.2%CVE-2025-33176MEDIUMNVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adEPSS 0.1%