Falhas do tipo CWE-923

74 resultados

Falta de restrição adequada do canal de comunicação aos endpoints pretendidos

A aplicação não valida ou restringe corretamente com quem está se comunicando, permitindo que dados sejam enviados ou recebidos de endpoints não autorizados. Isso abre caminho para ataques de man-in-the-middle, desvio de tráfego ou acesso a informações sensíveis por atores não pretendidos.

Exemplo

Uma app móvel se conecta a um servidor backend sem validar certificados SSL, aceitando conexões de qualquer servidor que se apresente com o nome correto. Um atacante na rede local intercepta e redireciona o tráfego para sua própria máquina, capturando credenciais e dados do usuário.

Como mitigar

Implemente validação rigorosa de certificados SSL/TLS (verificar chain, hostname e data), use pinning de certificados em apps críticas, e enforce HTTPS com headers HSTS. No backend, restrinja comunicação apenas aos IPs e domínios conhecidos, use firewalls e VPNs para isolamento de rede.

CVE-2022-43916MEDIUMIBM App Connect Enterprise Certified Container improper communications restrictionEPSS 0.3%CVE-2025-61939HIGHColumbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended EndpointsEPSS 0.3%CVE-2023-25518HIGH NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with pEPSS 0.3%CVE-2024-39271LOWImproper restriction of communication channel to intended endpoints in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software beforeEPSS 0.3%CVE-2026-34205CRITICALHome Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network ModeEPSS 0.3%CVE-2025-23178HIGHRibbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended EndpointsEPSS 0.3%CVE-2026-18655HIGHBroker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt InjectionEPSS 0.3%CVE-2026-59841MEDIUMA improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 maEPSS 0.2%CVE-2024-22315MEDIUMIBM Fusion improper communication restrictionEPSS 0.2%CVE-2024-36252MEDIUMImproper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If EPSS 0.2%CVE-2026-90461MEDIUMOpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) BEPSS 0.2%CVE-2026-22715MEDIUMVMware Workstation/Fusion NAT vulnerabilityEPSS 0.2%CVE-2026-22726MEDIUMRoute Services Firewall BypassEPSS 0.2%CVE-2026-81871MEDIUMOpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinningEPSS 0.2%CVE-2025-36180MEDIUMInadequate Pod Communication Restrictions, affects watsonx.dataEPSS 0.2%CVE-2025-58742HIGHInsufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirector CaptureEPSS 0.2%CVE-2022-2835MEDIUMA flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by theEPSS 0.2%CVE-2025-36145MEDIUMMultiple Vulnerabilities in watsonx.dataEPSS 0.2%CVE-2022-38125LOWFTP Agent forwards traffic on inactive ports to LinkManagerEPSS 0.2%CVE-2025-33176MEDIUMNVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adEPSS 0.1%