Fallos del tipo CWE-940

60 resultados

Verificação inadequada da origem de um canal de comunicação

A aplicação recebe dados por um canal de comunicação (rede, IPC, arquivo) sem validar corretamente se a origem é confiável. Um atacante se passa pela origem legítima, injetando dados maliciosos que o código processa como se fossem autênticos, comprometendo integridade e confidencialidade.

Ejemplo

Um servidor de aplicação aceita comandos administrativos via socket Unix sem verificar o UID do processo cliente. Um usuário comum se conecta ao socket e envia comandos como root, já que o servidor não valida quem está realmente do outro lado da conexão.

Cómo mitigar

Implemente verificação explícita da identidade do cliente antes de processar qualquer dado: valide certificados TLS, UIDs de processos, tokens assinados ou chaves pré-compartilhadas. Não assuma que apenas por estar em um canal 'privado' a origem é segura.

CVE-2025-25305HIGHSSL validation for outgoing requests in Home Assistant Core and used libs not correctEPSS 0.3%CVE-2025-23222HIGHAn issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, EPSS 0.2%CVE-2026-40434HIGHAnviz CrossChex Standard Improper Verification of Source of a Communication ChannelEPSS 0.2%CVE-2026-43880MEDIUMWWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From AddressEPSS 0.2%CVE-2026-89178HIGHHowyar|WeenyGenius - Origin Validation ErrorEPSS 0.2%CVE-2026-85085CRITICALThe Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page lEPSS 0.2%CVE-2025-43280MEDIUMThe issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remoEPSS 0.2%CVE-2024-0009MEDIUMPAN-OS: Improper IP Address Verification in GlobalProtect GatewayEPSS 0.2%CVE-2026-73419MEDIUMNextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created themEPSS 0.2%CVE-2026-85125MEDIUMThe Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. ThEPSS 0.2%CVE-2026-22269MEDIUMDell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerabEPSS 0.2%CVE-2025-20365MEDIUMA vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacEPSS 0.2%CVE-2023-7004MEDIUMCVE-2023-7004EPSS 0.2%CVE-2025-9999HIGHImproper validation of payload elementsEPSS 0.2%CVE-2025-0036LOWIn AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause dEPSS 0.1%CVE-2026-44894HIGHNetty's Default QUIC token handler accepts any client-supplied tokenEPSS 0.1%CVE-2025-62439LOWAn Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4,EPSS 0.1%CVE-2026-44698HIGHHome Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionEPSS 0.1%CVE-2025-42978LOWInsufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Application Server JavaEPSS 0.1%CVE-2026-45353CRITICALelecterm: Local code through electerm's single-instance socketEPSS 0.1%