Falhas do tipo CWE-16

62 resultados

Configuração Inadequada de Sistema ou Aplicação

É quando um software ou sistema é instalado, implantado ou mantido com configurações padrão inseguras, permissões excessivas ou parâmetros de segurança desabilitados. O risco é que atacantes exploram essas falhas de setup para ganhar acesso não autorizado ou elevar privilégios, porque a configuração nunca foi endurecida conforme o necessário.

Exemplo

Um servidor web com diretório de backup exposto publicamente (.git ou .bak visíveis), senhas padrão não alteradas em banco de dados, ou depuração habilitada em produção — tudo isso é resultado de má configuração e facilita invasões.

Como mitigar

Aplique checklist de segurança pós-instalação: mude credenciais padrão, desative recursos desnecessários, restrinja permissões de arquivo/acesso, revise logs e configs regularmente. Use infraestrutura como código (IaC) e templates pré-endurecidos para garantir consistência entre deployments.

CVE-2019-1585MEDIUMCisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Privilege Escalation VulnerabilityEPSS 0.4%CVE-2020-16247MEDIUMPhilips Clinical Collaboration Platform ConfigurationEPSS 0.4%CVE-2019-18579HIGHSettings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for thEPSS 0.3%CVE-2018-0275A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to accessEPSS 0.3%CVE-2020-8351HIGHA privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user toEPSS 0.3%CVE-2022-36423HIGHIncorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.EPSS 0.3%CVE-2022-28762HIGHDebugging port misconfiguration in Zoom Apps in the Zoom Client for Meetings for macOSEPSS 0.3%CVE-2023-43088HIGH Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the systemEPSS 0.3%CVE-2024-42031HIGHAccess permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect servicEPSS 0.3%CVE-2023-39392Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciouEPSS 0.2%CVE-2018-11922HIGHConfigurations in Android BuildEPSS 0.2%CVE-2021-21532MEDIUMDell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploitedEPSS 0.2%CVE-2024-47294MEDIUMAccess permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may EPSS 0.2%CVE-2017-12306A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade paEPSS 0.2%CVE-2026-4433LOWAn SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnEPSS 0.2%CVE-2023-52719HIGHPrivilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.2%CVE-2025-12221LOWCSRF Token not Properly ImplementedEPSS 0.2%CVE-2022-33233HIGHConfiguration weakness in modemEPSS 0.1%CVE-2026-56586LOWHCL IEM was affected with X-Content-Type-Options Header MissingEPSS 0.1%CVE-2024-47291MEDIUMPermission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availabEPSS 0.1%