Fallos del tipo CWE-941

11 resultados

Destino especificado incorretamente em canal de comunicação

Fraqueza em que o software envia dados sensíveis ou comandos para um destino (endpoint, servidor, usuário) incorreto ou não validado, devido a lógica de roteamento falha ou configuração errada. O risco é expor informações ou executar ações em contextos não pretendidos.

Ejemplo

Um sistema de notificações envia alertas de segurança para um telefone celular, mas o número armazenado no banco foi corrompido ou não validado; a mensagem é entregue ao número errado. Ou um serviço de API envia tokens de sessão para um endpoint de fallback sem validar se aquele endpoint é confiável.

Cómo mitigar

Sempre valide e verifique o destino antes de enviar dados: whitelist de endereços conhecidos, validação rigorosa de entrada de dados de destinatário, e implemente mecanismos de confirmação ou logging de roteamento. Testes de unidade que cobrem cenários de destino inválido são essenciais.

CVE-2024-29415HIGHThe ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, EPSS 8.3%CVE-2019-18242—In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiplEPSS 1.6%CVE-2025-53899HIGHKiteworks MFT is vulnerable to an Incorrectly Specified Destination in a Communication ChannelEPSS 0.9%CVE-2022-4847HIGHIncorrectly Specified Destination in a Communication Channel in usememos/memosEPSS 0.6%CVE-2023-33198MEDIUMIncorrectly Specified Chat Message Destinations in tgstation-server and DreamMaker APIEPSS 0.6%CVE-2025-69515CRITICALAn issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsifieEPSS 0.5%CVE-2024-34947CRITICALQuanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirectEPSS 0.4%CVE-2026-69246HIGHGuzzle: Noncanonical host can bypass host-based checksEPSS 0.4%CVE-2026-72506MEDIUMVoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination inEPSS 0.3%CVE-2026-40118MEDIUMUDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configuEPSS 0.2%CVE-2025-0036LOWIn AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause dEPSS 0.1%