CWE-420 · 40 records
Unprotected Alternate Channel
CVEs in this class
40 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2023-20198Weaponized | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Critical10.0 | KEV | 99.6% | Oct 16, 2023 |
97Now | CVE-2025-54309Weaponized | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allowscrushftp · crushftp · CWE-420 | Critical9.8 | KEV | 94.9% | Jul 18, 2025 |
47Plan | CVE-2025-13315Weaponized | Unauthenticated log access in Twonky Serverlinux · linux kernel · CWE-420 | Critical9.3 | — | 32.3% | Nov 19, 2025 |
40Plan | CVE-2023-31241No exploit | Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.snapone · orvc · CWE-420 | Critical10.0 | — | 0.8% | May 22, 2023 |
40Plan | CVE-2025-54351No exploit | In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).es · iperf3 · CWE-420 | Critical10.0 | — | 0.4% | Aug 2, 2025 |
39Monitor | CVE-2025-52921No exploit | In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution oinnoshop · innoshop · CWE-420 | Critical9.9 | — | 0.5% | Jun 23, 2025 |
36Monitor | CVE-2020-8558Proof of concept | Kubernetes node setting allows for neighboring hosts to bypass localhost boundarykubernetes · kubernetes · CWE-420 | High8.8 | — | 3.6% | Jul 27, 2020 |
36Monitor | CVE-2026-40217Proof of concept | LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.litellm · litellm · CWE-420 | High8.8 | — | 3.4% | Apr 10, 2026 |
35Monitor | CVE-2023-28840No exploit | moby/moby's dockerd daemon encrypted overlay network may be unauthenticatedmobyproject · moby · CWE-420 | High8.7 | — | 2.6% | Apr 4, 2023 |
35Monitor | CVE-2023-4570No exploit | Improper Restriction in NI MeasurementLink Python Servicesni · measurementlink · CWE-420 | High8.8 | — | 0.3% | Oct 5, 2023 |
35Monitor | GHSA-3926-2jvf-fg29No exploit | Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrailPyPI · litellm · CWE-420 | High8.8 | — | — | Apr 10, 2026 |
34Monitor | CVE-2025-53967No exploit | Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craftframelink · figma mcp server · CWE-420 | High8.0 | — | 5.8% | Oct 8, 2025 |
34Monitor | CVE-2025-62001No exploit | BullWall Ransomware Containment hard-coded folder exclusionsbullwall · ransomware containment · CWE-420 | High8.7 | — | 0.4% | Dec 18, 2025 |
34Monitor | CVE-2025-8557No exploit | An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a lenovo · xclarity orchestrator (lxco) · CWE-420 | High8.7 | — | 0.3% | Sep 11, 2025 |
32Monitor | CVE-2024-6242No exploit | Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devicesrockwell automation · controllogix® 5580 (1756-l8z) · CWE-420 | High7.3 | — | 11.1% | Aug 1, 2024 |
32Monitor | CVE-2023-7266No exploit | Some Huawei home routers have a connection hijacking vulnerability.huawei · tc7001-10 firmware · CWE-420 | High8.1 | — | 0.3% | Dec 28, 2024 |
32Monitor | CVE-2023-52718No exploit | A connection hijacking vulnerability exists in some Huawei home routers.huawei · pt9030-15 firmware · CWE-420 | High8.1 | — | 0.2% | Dec 28, 2024 |
31Monitor | CVE-2025-41727No exploit | Beckhoff: Performing privileged operations and gaining administrator accessbeckhoff automation · beckhoff.device.manager.xar · CWE-420 | High7.8 | — | 0.2% | Jan 27, 2026 |
31Monitor | CVE-2025-1095No exploit | IBM Personal Communications command executionibm · personal communications · CWE-420 | High7.8 | — | 0.1% | Apr 8, 2025 |
31Monitor | GHSA-85qf-6845-m8p2No exploit | Duplicate Advisory: Juju Unprotected Alternate Channel vulnerabilityGo · github.com/juju/juju · CWE-420 | High7.9 | — | — | Oct 2, 2024 |
30Monitor | CVE-2025-67303Proof of concept | An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.comfy · comfyui-manager · CWE-420 | High7.5 | — | 1.4% | Jan 5, 2026 |
30Monitor | GHSA-2hc9-cc65-xwj8No exploit | Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)PyPI · comfyui-manager · CWE-420 | High7.5 | — | — | Jan 5, 2026 |
29Monitor | CVE-2025-59033No exploit | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.microsoft · windows · CWE-420 | High7.4 | — | 0.3% | Sep 8, 2025 |
27Monitor | CVE-2023-28842No exploit | moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedmobyproject · moby · CWE-420 | Medium6.8 | — | 1.4% | Apr 4, 2023 |
27Monitor | CVE-2026-40435No exploit | BIG-IP httpd access control vulnerabilityf5 · big-ip access policy manager · CWE-420 | Medium6.9 | — | 0.3% | May 13, 2026 |
- CVE-2023-20198100Now
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
CriticalCVSS 10.0KEVWeaponizedEPSS 100%cisco · ios xeOct 16, 2023
- CVE-2025-5430997Now
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows
CriticalCVSS 9.8KEVWeaponizedEPSS 95%crushftp · crushftpJul 18, 2025
- CVE-2025-1331547Plan
Unauthenticated log access in Twonky Server
CriticalCVSS 9.3WeaponizedEPSS 32%linux · linux kernelNov 19, 2025
- CVE-2023-3124140Plan
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
CriticalCVSS 10.0No exploitEPSS 1%snapone · orvcMay 22, 2023
- CVE-2025-5435140Plan
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
CriticalCVSS 10.0No exploitEPSS 0%es · iperf3Aug 2, 2025
- CVE-2025-5292139Monitor
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution o
CriticalCVSS 9.9No exploitEPSS 1%innoshop · innoshopJun 23, 2025
- CVE-2020-855836Monitor
Kubernetes node setting allows for neighboring hosts to bypass localhost boundary
HighCVSS 8.8Proof of conceptEPSS 4%kubernetes · kubernetesJul 27, 2020
- CVE-2026-4021736Monitor
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
HighCVSS 8.8Proof of conceptEPSS 3%litellm · litellmApr 10, 2026
- CVE-2023-2884035Monitor
moby/moby's dockerd daemon encrypted overlay network may be unauthenticated
HighCVSS 8.7No exploitEPSS 3%mobyproject · mobyApr 4, 2023
- CVE-2023-457035Monitor
Improper Restriction in NI MeasurementLink Python Services
HighCVSS 8.8No exploitEPSS 0%ni · measurementlinkOct 5, 2023
- GHSA-3926-2jvf-fg2935Monitor
Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail
HighCVSS 8.8No exploitPyPI · litellmApr 10, 2026
- CVE-2025-5396734Monitor
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a craft
HighCVSS 8.0No exploitEPSS 6%framelink · figma mcp serverOct 8, 2025
- CVE-2025-6200134Monitor
BullWall Ransomware Containment hard-coded folder exclusions
HighCVSS 8.7No exploitEPSS 0%bullwall · ransomware containmentDec 18, 2025
- CVE-2025-855734Monitor
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a
HighCVSS 8.7No exploitEPSS 0%lenovo · xclarity orchestrator (lxco)Sep 11, 2025
- CVE-2024-624232Monitor
Rockwell Automation Chassis Restrictions Bypass Vulnerability in Select Logix Devices
HighCVSS 7.3No exploitEPSS 11%rockwell automation · controllogix® 5580 (1756-l8z)Aug 1, 2024
- CVE-2023-726632Monitor
Some Huawei home routers have a connection hijacking vulnerability.
HighCVSS 8.1No exploitEPSS 0%huawei · tc7001-10 firmwareDec 28, 2024
- CVE-2023-5271832Monitor
A connection hijacking vulnerability exists in some Huawei home routers.
HighCVSS 8.1No exploitEPSS 0%huawei · pt9030-15 firmwareDec 28, 2024
- CVE-2025-4172731Monitor
Beckhoff: Performing privileged operations and gaining administrator access
HighCVSS 7.8No exploitEPSS 0%beckhoff automation · beckhoff.device.manager.xarJan 27, 2026
- CVE-2025-109531Monitor
IBM Personal Communications command execution
HighCVSS 7.8No exploitEPSS 0%ibm · personal communicationsApr 8, 2025
- GHSA-85qf-6845-m8p231Monitor
Duplicate Advisory: Juju Unprotected Alternate Channel vulnerability
HighCVSS 7.9No exploitGo · github.com/juju/jujuOct 2, 2024
- CVE-2025-6730330Monitor
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.
HighCVSS 7.5Proof of conceptEPSS 1%comfy · comfyui-managerJan 5, 2026
- GHSA-2hc9-cc65-xwj830Monitor
Duplicate Advisory: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)
HighCVSS 7.5No exploitPyPI · comfyui-managerJan 5, 2026
- CVE-2025-5903329Monitor
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy.
HighCVSS 7.4No exploitEPSS 0%microsoft · windowsSep 8, 2025
- CVE-2023-2884227Monitor
moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated
MediumCVSS 6.8No exploitEPSS 1%mobyproject · mobyApr 4, 2023
- CVE-2026-4043527Monitor
BIG-IP httpd access control vulnerability
MediumCVSS 6.9No exploitEPSS 0%f5 · big-ip access policy managerMay 13, 2026