CWE-300 · 57 записей
Channel Accessible by Non-Endpoint
CVE этого класса
57 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-7480Эксплойта нет | rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remotrootkit hunter project · rootkit hunter · CWE-300 | Критическая9,8 | — | 2,3 % | 21 июл. 2017 г. |
39Наблюдать | CVE-2019-3793Эксплойта нет | Invitations Service supports HTTP connectionspivotal software · application service · CWE-300 | Критическая9,8 | — | 1,1 % | 24 апр. 2019 г. |
37Наблюдать | CVE-2026-74232Эксплойта нет | Zbtlink MQWrt yunmgrd Cloud C2 Implantzbtlink · l3_v2_8 · CWE-300 | Критическая9,3 | — | 0,8 % | 27 авг. 2026 г. |
37Наблюдать | CVE-2025-54792Эксплойта нет | LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interceptionlocalsend · localsend · CWE-300 | Критическая9,3 | — | 0,3 % | 1 авг. 2025 г. |
36Наблюдать | CVE-2023-31004Эксплойта нет | IBM Security Access Manager Container gain accessibm · security verify access · CWE-300 | Критическая9,0 | — | 1,0 % | 2 февр. 2024 г. |
34Наблюдать | CVE-2026-12991Эксплойта нет | Multiple vulnerabilities in Ghost Robotics' Vision 60ghost robotics · vision 60 · CWE-300 | Высокая8,7 | — | 0,2 % | 27 июл. 2026 г. |
33Наблюдать | CVE-2017-12150Эксплойта нет | It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration samba · samba · CWE-300 | Высокая7,4 | — | 13,3 % | 26 июл. 2018 г. |
32Наблюдать | CVE-2018-0025Эксплойта нет | Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authenticationjuniper · junos · CWE-300 | Высокая8,1 | — | 1,4 % | 11 июл. 2018 г. |
32Наблюдать | CVE-2019-5456Эксплойта нет | SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP ui · unifi controller · CWE-300 | Высокая8,1 | — | 1,3 % | 30 июл. 2019 г. |
32Наблюдать | CVE-2021-41033Эксплойта нет | In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middeclipse · equinox · CWE-300 | Высокая8,1 | — | 1,1 % | 13 сент. 2021 г. |
32Наблюдать | CVE-2021-21953Эксплойта нет | An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.anker · eufy homebase 2 firmware · CWE-300 | Высокая8,1 | — | 1,0 % | 22 дек. 2021 г. |
32Наблюдать | CVE-2018-13298Эксплойта нет | Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attacsynology · moments · CWE-300 | Высокая8,1 | — | 0,9 % | 1 апр. 2019 г. |
32Наблюдать | CVE-2020-11024Эксплойта нет | Man-in-the-middle attack in Moonlight iOS/tvOSmoonlight-stream · moonlight · CWE-300 | Высокая8,2 | — | 0,8 % | 29 апр. 2020 г. |
32Наблюдать | CVE-2025-31214Эксплойта нет | This issue was addressed through improved state management.apple · ipados · CWE-300 | Высокая8,1 | — | 0,5 % | 12 мая 2025 г. |
32Наблюдать | CVE-2024-31206Эксплойта нет | Use of Unencrypted HTTP Request in dectalk-ttsjstnmcbrd · dectalk-tts · CWE-300 | Высокая8,2 | — | 0,3 % | 4 апр. 2024 г. |
32Наблюдать | CVE-2024-36553Эксплойта нет | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.CWE-300 | Высокая8,1 | — | 0,3 % | 6 февр. 2025 г. |
32Наблюдать | GHSA-j3rq-4xjw-xg63Эксплойта нет | Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacksGo · github.com/edgelesssys/marblerun · CWE-300 | Высокая8,0 | — | — | 4 дек. 2023 г. |
31Наблюдать | CVE-2021-32926Эксплойта нет | When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includerockwellautomation · micro800 firmware · CWE-300 | Высокая7,5 | — | 3,0 % | 3 июн. 2021 г. |
31Наблюдать | CVE-2025-20122Эксплойта нет | Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerabilitycisco · catalyst sd-wan manager · CWE-300 | Высокая7,8 | — | 0,1 % | 7 мая 2025 г. |
30Наблюдать | CVE-2017-12151Эксплойта нет | A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3samba · samba · CWE-300 | Высокая7,4 | — | 4,6 % | 27 июл. 2018 г. |
30Наблюдать | CVE-2017-15086Эксплойта нет | It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEredhat · gluster storage · CWE-300 | Высокая7,4 | — | 1,7 % | 8 нояб. 2017 г. |
30Наблюдать | CVE-2021-22909Эксплойта нет | A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack duui · edgemax edgerouter firmware · CWE-300 | Высокая7,5 | — | 1,3 % | 27 мая 2021 г. |
30Наблюдать | CVE-2024-50565Эксплойта нет | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.fortinet · fortiweb · CWE-300 | Высокая7,5 | — | 0,4 % | 8 апр. 2025 г. |
30Наблюдать | CVE-2023-38272Эксплойта нет | IBM Cloud Pak System information disclosureibm · cloud pak system · CWE-300 | Высокая7,5 | — | 0,3 % | 27 мар. 2025 г. |
30Наблюдать | CVE-2024-12602Эксплойта нет | Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confhuawei · harmonyos · CWE-300 | Высокая7,5 | — | 0,2 % | 6 февр. 2025 г. |
- CVE-2017-748040В плане
rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remot
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rootkit hunter project · rootkit hunter21 июл. 2017 г.
- CVE-2019-379339Наблюдать
Invitations Service supports HTTP connections
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pivotal software · application service24 апр. 2019 г.
- CVE-2026-7423237Наблюдать
Zbtlink MQWrt yunmgrd Cloud C2 Implant
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %zbtlink · l3_v2_827 авг. 2026 г.
- CVE-2025-5479237Наблюдать
LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %localsend · localsend1 авг. 2025 г.
- CVE-2023-3100436Наблюдать
IBM Security Access Manager Container gain access
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %ibm · security verify access2 февр. 2024 г.
- CVE-2026-1299134Наблюдать
Multiple vulnerabilities in Ghost Robotics' Vision 60
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %ghost robotics · vision 6027 июл. 2026 г.
- CVE-2017-1215033Наблюдать
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration
ВысокаяCVSS 7,4Эксплойта нетEPSS 13 %samba · samba26 июл. 2018 г.
- CVE-2018-002532Наблюдать
Junos OS: SRX Series: Credentials exposed when using HTTP and HTTPS Firewall Pass-through User Authentication
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %juniper · junos11 июл. 2018 г.
- CVE-2019-545632Наблюдать
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %ui · unifi controller30 июл. 2019 г.
- CVE-2021-4103332Наблюдать
In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-midd
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %eclipse · equinox13 сент. 2021 г.
- CVE-2021-2195332Наблюдать
An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %anker · eufy homebase 2 firmware22 дек. 2021 г.
- CVE-2018-1329832Наблюдать
Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attac
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %synology · moments1 апр. 2019 г.
- CVE-2020-1102432Наблюдать
Man-in-the-middle attack in Moonlight iOS/tvOS
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %moonlight-stream · moonlight29 апр. 2020 г.
- CVE-2025-3121432Наблюдать
This issue was addressed through improved state management.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %apple · ipados12 мая 2025 г.
- CVE-2024-3120632Наблюдать
Use of Unencrypted HTTP Request in dectalk-tts
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %jstnmcbrd · dectalk-tts4 апр. 2024 г.
- CVE-2024-3655332Наблюдать
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %6 февр. 2025 г.
- GHSA-j3rq-4xjw-xg6332Наблюдать
Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacks
ВысокаяCVSS 8,0Эксплойта нетGo · github.com/edgelesssys/marblerun4 дек. 2023 г.
- CVE-2021-3292631Наблюдать
When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that include
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %rockwellautomation · micro800 firmware3 июн. 2021 г.
- CVE-2025-2012231Наблюдать
Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %cisco · catalyst sd-wan manager7 мая 2025 г.
- CVE-2017-1215130Наблюдать
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3
ВысокаяCVSS 7,4Эксплойта нетEPSS 5 %samba · samba27 июл. 2018 г.
- CVE-2017-1508630Наблюдать
It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHE
ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %redhat · gluster storage8 нояб. 2017 г.
- CVE-2021-2290930Наблюдать
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack du
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ui · edgemax edgerouter firmware27 мая 2021 г.
- CVE-2024-5056530Наблюдать
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %fortinet · fortiweb8 апр. 2025 г.
- CVE-2023-3827230Наблюдать
IBM Cloud Pak System information disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · cloud pak system27 мар. 2025 г.
- CVE-2024-1260230Наблюдать
Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service conf
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %huawei · harmonyos6 февр. 2025 г.