Falhas do tipo CWE-16

62 resultados

Configuração Inadequada de Sistema ou Aplicação

É quando um software ou sistema é instalado, implantado ou mantido com configurações padrão inseguras, permissões excessivas ou parâmetros de segurança desabilitados. O risco é que atacantes exploram essas falhas de setup para ganhar acesso não autorizado ou elevar privilégios, porque a configuração nunca foi endurecida conforme o necessário.

Exemplo

Um servidor web com diretório de backup exposto publicamente (.git ou .bak visíveis), senhas padrão não alteradas em banco de dados, ou depuração habilitada em produção — tudo isso é resultado de má configuração e facilita invasões.

Como mitigar

Aplique checklist de segurança pós-instalação: mude credenciais padrão, desative recursos desnecessários, restrinja permissões de arquivo/acesso, revise logs e configs regularmente. Use infraestrutura como código (IaC) e templates pré-endurecidos para garantir consistência entre deployments.

CVE-2019-19089MEDIUMeSOMS: X-Content-Type-Options Header MissingEPSS 1.1%CVE-2022-22183HIGHJunos OS Evolved: A remote attacker may cause a CPU Denial of Service by sending genuine traffic to a device on a specific IPv4 port.EPSS 1.0%CVE-2021-35233MEDIUMHTTP TRACK & TRACE Methods EnabledEPSS 1.0%CVE-2022-43516MEDIUMZabbix Agent installer adds “allow all TCP any any” firewall ruleEPSS 0.9%CVE-2021-22957A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor EPSS 0.9%CVE-2022-37397HIGHThe software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active DirectoryEPSS 0.9%CVE-2019-19092LOWABB eSOMS: Viewstate without MAC SignatureEPSS 0.8%CVE-2019-19002MEDIUMABB eSOMS X-XSS-Protection not enabledEPSS 0.8%CVE-2019-19003MEDIUMABB eSOMS: HTTPOnly flag not setEPSS 0.8%CVE-2019-19091MEDIUMABB eSOMS: HTTP response information leakageEPSS 0.8%CVE-2023-33105HIGHConfiguration Issue in WLAN Host and FirmwareEPSS 0.8%CVE-2018-0263A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal devicEPSS 0.7%CVE-2019-19097MEDIUMABB eSOMS: SSL medium strength Cipher SuitesEPSS 0.7%CVE-2021-0222HIGHJunos OS: Upon receipt of certain protocol packets with invalid payloads a self-propagating Denial of Service may occur.EPSS 0.6%CVE-2020-8353MEDIUMPrior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) featureEPSS 0.6%CVE-2024-32991HIGHPermission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availabEPSS 0.5%CVE-2019-19090LOWABB eSOMS: Secure Flag not setEPSS 0.5%CVE-2019-1829MEDIUMCisco Aironet Series Access Points Command Injection VulnerabilityEPSS 0.4%CVE-2023-39385Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unaEPSS 0.4%CVE-2025-20151MEDIUMCisco IOS and IOS XE Software SNMPv3 Configuration Restriction VulnerabilityEPSS 0.4%