Fallos del tipo CWE-940

60 resultados

Verificação inadequada da origem de um canal de comunicação

A aplicação recebe dados por um canal de comunicação (rede, IPC, arquivo) sem validar corretamente se a origem é confiável. Um atacante se passa pela origem legítima, injetando dados maliciosos que o código processa como se fossem autênticos, comprometendo integridade e confidencialidade.

Ejemplo

Um servidor de aplicação aceita comandos administrativos via socket Unix sem verificar o UID do processo cliente. Um usuário comum se conecta ao socket e envia comandos como root, já que o servidor não valida quem está realmente do outro lado da conexão.

Cómo mitigar

Implemente verificação explícita da identidade do cliente antes de processar qualquer dado: valide certificados TLS, UIDs de processos, tokens assinados ou chaves pré-compartilhadas. Não assuma que apenas por estar em um canal 'privado' a origem é segura.

CVE-2024-26131HIGHElement Android Intent RedirectionEPSS 0.5%CVE-2026-23866MEDIUMIncomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for AndroidEPSS 0.5%CVE-2024-20390MEDIUMCisco IOS XR Software Dedicated XML Agent TCP Denial of Service VulnerabilityEPSS 0.4%CVE-2024-49579HIGHIn JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requestsEPSS 0.4%CVE-2024-40503MEDIUMAn issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packetEPSS 0.4%CVE-2026-2611CRITICALImproper Origin Validation in mlflow/mlflowEPSS 0.4%CVE-2024-37662MEDIUMTP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijacEPSS 0.4%CVE-2024-37664MEDIUMRedmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijackEPSS 0.4%CVE-2026-35643HIGHOpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterfaceEPSS 0.4%CVE-2024-1621HIGHuniFLOW Online device registration susceptible to compromiseEPSS 0.4%CVE-2026-78685HIGHLe-yan|Medical Practice Management System - Remote Code ExecutionEPSS 0.3%CVE-2026-6734HIGHundici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuseEPSS 0.3%CVE-2026-45245MEDIUMSummarize < 0.15.1 Unauthorized Daemon Request via Untrusted EventsEPSS 0.3%CVE-2024-40516HIGHAn issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the RoutingEPSS 0.3%CVE-2026-48745CRITICALTraccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetryEPSS 0.3%CVE-2024-7322MEDIUMDos in ZigBee device due to unsolicited encrypted rejoin responseEPSS 0.3%CVE-2024-37663MEDIUMRedmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the tEPSS 0.3%CVE-2026-55660HIGHTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeoverEPSS 0.3%CVE-2026-33875CRITICALAuthenticator Vulnerable to Authentication Flow HijackEPSS 0.3%CVE-2025-59159CRITICALSillyTavern Web Interface Vulnerable to DNS RebindingEPSS 0.3%