Falhas do tipo CWE-420

37 resultados

Canal alternativo desprotegido

Ocorre quando uma aplicação oferece um meio alternativo de acesso ou comunicação (como API backdoor, porta de debug, interface administrativa oculta) que não possui os mesmos controles de segurança que o canal principal. Um atacante que descobre esse caminho paralelo consegue contornar autenticação, autorização ou criptografia implementadas na rota legítima.

Exemplo

Um servidor web exige login HTTPS no portal /admin, mas expõe a mesma funcionalidade sem autenticação em /debug/admin via HTTP. Ou um firmware deixa uma porta SSH aberta apenas para testes internos, esquecida em produção. O atacante acessa dados sensíveis ou controla a aplicação pelo canal fraco.

Como mitigar

Identifique e documente todos os canais de comunicação e interfaces (APIs, portas, endpoints ocultos). Aplique o mesmo nível de autenticação, autorização e criptografia em todos eles. Em produção, desative ou remova completamente canais de debug, desenvolvimento ou administração que não são necessários para operação legítima.

CVE-2023-20198CRITICALCisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We areEPSS 99.6%KEVCVE-2025-54309CRITICALCrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allowsEPSS 92.0%KEVCVE-2024-10081CRITICALCodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypasEPSS 39.0%CVE-2025-13315CRITICALUnauthenticated log access in Twonky ServerEPSS 32.9%CVE-2024-6242HIGHRockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix DevicesEPSS 9.2%CVE-2025-53967HIGHFramelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craftEPSS 7.4%CVE-2026-40217HIGHLiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.EPSS 6.5%CVE-2020-8558MEDIUMKubernetes node setting allows for neighboring hosts to bypass localhost boundaryEPSS 3.6%CVE-2023-28840HIGHmoby/moby's dockerd daemon encrypted overlay network may be unauthenticatedEPSS 2.7%CVE-2023-28842MEDIUMmoby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedEPSS 1.4%CVE-2025-67303HIGHAn issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. ThEPSS 1.4%CVE-2023-31241HIGHSnap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.EPSS 0.8%CVE-2024-4444MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User RegistrationEPSS 0.7%CVE-2022-25786MEDIUMGateManager debug interface is included in production buildsEPSS 0.7%CVE-2026-25916MEDIUMRoundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.EPSS 0.6%CVE-2023-0317MEDIUMGateManager debug interface is included in non-debug buildsEPSS 0.5%CVE-2025-52921CRITICALIn Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution oEPSS 0.5%CVE-2024-6099MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User RegistrationEPSS 0.4%CVE-2025-54351HIGHIn iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).EPSS 0.4%CVE-2023-30946LOWIssues notification metadata lacks authorizationEPSS 0.4%