Falhas do tipo CWE-940

55 resultados

Verificação inadequada da origem de um canal de comunicação

A aplicação recebe dados por um canal de comunicação (rede, API, arquivo, etc.) sem validar adequadamente se a origem é confiável ou autorizada. O código assume que a mensagem veio de quem deveria, mas não implementa mecanismos suficientes (autenticação, assinatura digital, TLS mútuo) para confirmar isso. Um atacante pode se passar pela origem legítima e injetar dados maliciosos.

Exemplo

Um serviço backend consome eventos de um tópico MQTT ou fila de mensagens sem verificar assinatura ou certificado do produtor. Um atacante na mesma rede publica mensagens falsas que são processadas como se fossem de um sistema confiável, causando efeitos não autorizados.

Como mitigar

Implemente autenticação mútua (certificados X.509, OAuth 2.0, ou chaves compartilhadas assinadas); valide assinatura criptográfica de cada mensagem crítica; use canais de comunicação seguros e criptografados (TLS com validação de certificado); e aplique controle de acesso baseado na identidade verificada da origem.

CVE-2025-61932CRITICALLanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, EPSS 2.6%KEVCVE-2024-32388MEDIUMDue to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allowEPSS 1.2%CVE-2023-48387HIGHTAIWAN-CA(TWCA) JCICSecurityTool - Improper Input ValidationEPSS 1.0%CVE-2025-23018MEDIUMIPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowingEPSS 1.0%CVE-2023-3663HIGHCODESYS: Missing integrity check in CODESYS Development SystemEPSS 1.0%CVE-2025-23019MEDIUMIPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.EPSS 0.9%CVE-2021-41038In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().EPSS 0.7%CVE-2024-40515CRITICALAn issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the RoutinEPSS 0.7%CVE-2024-38886CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 0.6%CVE-2025-13086MEDIUMImproper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to openEPSS 0.6%CVE-2023-41355CRITICALChunghwa Telecom NOKIA G-040W-Q - Improper Input ValidationEPSS 0.6%CVE-2023-51440HIGHA vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0) (AllEPSS 0.6%CVE-2022-4800HIGHImproper Verification of Source of a Communication Channel in usememos/memosEPSS 0.6%CVE-2023-41094CRITICALTouchlink authentication bypass due to packets processed after timeout or out of range in Ember ZNetEPSS 0.6%CVE-2022-4848HIGHImproper Verification of Source of a Communication Channel in usememos/memosEPSS 0.5%CVE-2019-25613HIGHEasy Chat Server 3.1 Denial of Service via message ParameterEPSS 0.5%CVE-2024-36506LOWAn improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all EPSS 0.5%CVE-2026-2967MEDIUMCesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of sourceEPSS 0.5%CVE-2026-54106MEDIUMU.S. GAO EPDS and CBCA EDS network access control bypassEPSS 0.5%CVE-2025-40820HIGHAffected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This EPSS 0.5%