Fallos del tipo CWE-923

74 resultados

Restrição inadequada de canal de comunicação para endpoints pretendidos

Ocorre quando a aplicação não valida corretamente se está se comunicando com o endpoint correto, permitindo que um atacante intercepte, redirecione ou substitua a comunicação. O código assume que está falando com o servidor legítimo sem verificar identidade, certificados ou origem, criando janelas para man-in-the-middle ou redirecionamento malicioso.

Ejemplo

Uma app mobile conecta a um servidor via HTTP sem validar certificado SSL/TLS, ou aceita qualquer certificado autoassinado. Um atacante na mesma rede WiFi intercepta a conexão e serve credenciais falsas; a app não detecta porque não verificou a autenticidade do servidor.

Cómo mitigar

Sempre validar certificados SSL/TLS (fixar certificado público se possível), usar HTTPS obrigatório, implementar verificação de hostname, e em APIs internas usar autenticação mútua (mTLS). Nunca confiar em claims do servidor sem validação criptográfica.

CVE-2025-33176MEDIUMNVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adEPSS 0.1%CVE-2026-12039MEDIUMDocker Sandboxes network egress allowlist bypass via unfiltered DNS resolutionEPSS 0.1%CVE-2025-32886MEDIUMAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB EPSS 0.1%CVE-2024-47125HIGHImproper Restriction of Communication Channel to Intended Endpoints in goTenna ProEPSS 0.1%CVE-2025-27769LOWA vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging SEPSS 0.1%CVE-2026-12539MEDIUMDocker Sandboxes ICMP egress restriction bypass after daemon restartEPSS 0.1%CVE-2025-35978MEDIUMImproper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService EPSS 0.1%CVE-2025-36438MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.1%CVE-2026-8920HIGHImproper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service alloEPSS 0.1%CVE-2026-32303HIGHCryptomator: Tampered vault configuration allows MITM attack on Hub APIEPSS 0.1%CVE-2022-30729LOWImplicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a maEPSS 0.1%CVE-2026-55655MEDIUMOpenssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versionsEPSS 0.1%CVE-2026-32318HIGHCryptomator for IOS: Tampered vault configuration allows MITM attack on Hub APIEPSS 0.1%CVE-2026-32317HIGHCryptomator for Android: Tampered vault configuration allows MITM attack on Hub APIEPSS 0.1%