Falhas do tipo CWE-940

60 resultados

Verificação inadequada da origem de um canal de comunicação

A aplicação recebe dados por um canal de comunicação (rede, API, arquivo, etc.) sem validar adequadamente se a origem é confiável ou autorizada. O código assume que a mensagem veio de quem deveria, mas não implementa mecanismos suficientes (autenticação, assinatura digital, TLS mútuo) para confirmar isso. Um atacante pode se passar pela origem legítima e injetar dados maliciosos.

Exemplo

Um serviço backend consome eventos de um tópico MQTT ou fila de mensagens sem verificar assinatura ou certificado do produtor. Um atacante na mesma rede publica mensagens falsas que são processadas como se fossem de um sistema confiável, causando efeitos não autorizados.

Como mitigar

Implemente autenticação mútua (certificados X.509, OAuth 2.0, ou chaves compartilhadas assinadas); valide assinatura criptográfica de cada mensagem crítica; use canais de comunicação seguros e criptografados (TLS com validação de certificado); e aplique controle de acesso baseado na identidade verificada da origem.

CVE-2025-25305HIGHSSL validation for outgoing requests in Home Assistant Core and used libs not correctEPSS 0.3%CVE-2025-23222HIGHAn issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, EPSS 0.2%CVE-2026-40434HIGHAnviz CrossChex Standard Improper Verification of Source of a Communication ChannelEPSS 0.2%CVE-2026-43880MEDIUMWWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From AddressEPSS 0.2%CVE-2026-89178HIGHHowyar|WeenyGenius - Origin Validation ErrorEPSS 0.2%CVE-2026-85085CRITICALThe Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page lEPSS 0.2%CVE-2025-43280MEDIUMThe issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remoEPSS 0.2%CVE-2024-0009MEDIUMPAN-OS: Improper IP Address Verification in GlobalProtect GatewayEPSS 0.2%CVE-2026-73419MEDIUMNextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created themEPSS 0.2%CVE-2026-85125MEDIUMThe Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. ThEPSS 0.2%CVE-2026-22269MEDIUMDell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerabEPSS 0.2%CVE-2025-20365MEDIUMA vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacEPSS 0.2%CVE-2023-7004MEDIUMCVE-2023-7004EPSS 0.2%CVE-2025-9999HIGHImproper validation of payload elementsEPSS 0.2%CVE-2025-0036LOWIn AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause dEPSS 0.1%CVE-2026-44894HIGHNetty's Default QUIC token handler accepts any client-supplied tokenEPSS 0.1%CVE-2025-62439LOWAn Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4,EPSS 0.1%CVE-2026-44698HIGHHome Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionEPSS 0.1%CVE-2025-42978LOWInsufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Application Server JavaEPSS 0.1%CVE-2026-45353CRITICALelecterm: Local code through electerm's single-instance socketEPSS 0.1%