Falhas do tipo CWE-923

74 resultados

Falta de restrição adequada do canal de comunicação aos endpoints pretendidos

A aplicação não valida ou restringe corretamente com quem está se comunicando, permitindo que dados sejam enviados ou recebidos de endpoints não autorizados. Isso abre caminho para ataques de man-in-the-middle, desvio de tráfego ou acesso a informações sensíveis por atores não pretendidos.

Exemplo

Uma app móvel se conecta a um servidor backend sem validar certificados SSL, aceitando conexões de qualquer servidor que se apresente com o nome correto. Um atacante na rede local intercepta e redireciona o tráfego para sua própria máquina, capturando credenciais e dados do usuário.

Como mitigar

Implemente validação rigorosa de certificados SSL/TLS (verificar chain, hostname e data), use pinning de certificados em apps críticas, e enforce HTTPS com headers HSTS. No backend, restrinja comunicação apenas aos IPs e domínios conhecidos, use firewalls e VPNs para isolamento de rede.

CVE-2024-26013HIGHA improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.EPSS 0.5%CVE-2026-78501HIGHMicrosoft 365 Copilot Business Chat Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-31144MEDIUMQuick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, aEPSS 0.5%CVE-2025-48807MEDIUMWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-26131HIGHElement Android Intent RedirectionEPSS 0.5%CVE-2025-20261HIGHCisco Integrated Management Controller Privilege Escalation VulnerabilityEPSS 0.5%CVE-2026-62836HIGHAzure SQL Managed Instance Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-29108MEDIUMIP filter vulnerability in ABAP Platform and SAP Web Dispatcher EPSS 0.4%CVE-2025-22251LOWAn improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 alEPSS 0.4%CVE-2023-44195MEDIUMJunos OS Evolved: Packets which are not destined to the router can reach the REEPSS 0.4%CVE-2022-2837MEDIUMA flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod thEPSS 0.4%CVE-2023-28971HIGHParagon Active Assurance: Enabling the timescaledb enables IP forwardingEPSS 0.4%CVE-2026-63226MEDIUMPrinters and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing toEPSS 0.4%CVE-2026-33803MEDIUMJunos OS Evolved: A port which has been inadvertently exposed can be reached by an attackerEPSS 0.4%CVE-2024-39537MEDIUMJunos OS Evolved: ACX7000 Series: Ports which have been inadvertently exposed can be reached over the networkEPSS 0.3%CVE-2025-49734HIGHPowerShell Direct Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-57028MEDIUMJunos OS Evolved: A port which has been inadvertently exposed can be reached by an attackerEPSS 0.3%CVE-2026-87734HIGHAn issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.EPSS 0.3%CVE-2025-29986HIGHDell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulneraEPSS 0.3%CVE-2025-62843LOWQuRouterEPSS 0.3%