Falhas do tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com uma configuração padrão insegura (como senha padrão, porta aberta, ou função habilitada por padrão) que deveria ser mudada na primeira execução ou durante a administração, mas não é. O desenvolvedor assume que o admin vai mudar, mas isso frequentemente não acontece, deixando a falha na produção.

Exemplo

Um servidor de banco de dados instalado com usuário 'admin' e senha 'admin123' como padrão, documentado que deve ser alterado na primeira inicialização. Se o administrador pula essa etapa ou a ignora, qualquer um consegue acessar o banco com credenciais triviais.

Como mitigar

Force a mudança de configurações críticas na primeira execução (bloqueie a aplicação até que defaults inseguros sejam alterados), forneça valores padrão aleatórios e únicos por instalação, ou use setup assistido que não permite prosseguir sem trocar credenciais e permissões perigosas.

CVE-2023-48733MEDIUMAn insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure BootEPSS 0.3%CVE-2021-33130MEDIUMInsecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated useEPSS 0.3%CVE-2025-43015HIGHIn JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfacesEPSS 0.3%CVE-2024-5801MEDIUMIP Forwarding enabled in B&R Automation RuntimeEPSS 0.3%CVE-2025-2442MEDIUMCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unauthorized access whicEPSS 0.2%CVE-2026-41931MEDIUMVvveb < 1.0.8.2 Information Disclosure via Debug Exception HandlerEPSS 0.2%CVE-2025-43797MEDIUMIn Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through EPSS 0.2%CVE-2026-77348HIGHWallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`EPSS 0.2%CVE-2026-65881HIGHJoomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1EPSS 0.2%CVE-2026-9680MEDIUMMCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-serverEPSS 0.2%CVE-2022-24287HIGHA vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 VEPSS 0.2%CVE-2026-75062CRITICALEval Injection in google/langfun via default lf.query protocolEPSS 0.2%CVE-2026-54800MEDIUMA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < VEPSS 0.2%CVE-2026-40994HIGHWss4jSecurityInterceptor disables WS-I BSP validation by defaultEPSS 0.2%CVE-2026-33072HIGHFileRise: Default Encryption Key Enables Token Forgery and Config DecryptionEPSS 0.2%CVE-2025-2441MEDIUMCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicEPSS 0.2%CVE-2025-62802MEDIUMDNN CKEditor Provider allows unauthenticated upload out-of-the-boxEPSS 0.2%CVE-2026-20265MEDIUMInsecure Default Domain Allowlist in Splunk AI ToolkitEPSS 0.2%CVE-2024-8313HIGHDefault or Guessable SNMP community names in B&R APROLEPSS 0.2%CVE-2026-43581CRITICALOpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay BindingEPSS 0.2%