CWE-923 · 63 записей
Improper Restriction of Communication Channel to Intended Endpoints
CVE этого класса
63 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-17440Эксплойта нет | PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root accesspaloaltonetworks · pan-os · CWE-923 | Критическая9,8 | — | 1,7 % | 20 дек. 2019 г. |
40В плане | CVE-2026-62836Эксплойта нет | Azure SQL Managed Instance Elevation of Privilege Vulnerabilitymicrosoft · azure sql managed instance · CWE-923 | Критическая10,0 | — | 0,6 % | 6 авг. 2026 г. |
39Наблюдать | CVE-2024-41889Эксплойта нет | Multiple Pimax products accept WebSocket connections from unintended endpoints.pimax · pitool · CWE-923 | Критическая9,8 | — | 0,7 % | 5 авг. 2024 г. |
38Наблюдать | CVE-2017-3891Эксплойта нет | In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNXblackberry · qnx software development platform · CWE-923 | Критическая9,6 | — | 1,3 % | 14 нояб. 2017 г. |
38Наблюдать | CVE-2026-34205Эксплойта нет | Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Modehome-assistant · home assistant operating system · CWE-923 | Критическая9,6 | — | 0,3 % | 27 мар. 2026 г. |
36Наблюдать | CVE-2023-28078Эксплойта нет | Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured.dell · smartfabric os10 · CWE-923 | Критическая9,1 | — | 0,9 % | 15 февр. 2024 г. |
36Наблюдать | CVE-2022-43916Эксплойта нет | IBM App Connect Enterprise Certified Container improper communications restrictionibm · app connect enterprise certified container · CWE-923 | Критическая9,1 | — | 0,3 % | 30 янв. 2025 г. |
35Наблюдать | CVE-2025-20261Эксплойта нет | Cisco Integrated Management Controller Privilege Escalation Vulnerabilitycisco · cisco unified computing system (managed) · CWE-923 | Высокая8,8 | — | 0,5 % | 4 июн. 2025 г. |
34Наблюдать | CVE-2025-61939Эксплойта нет | Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpointscolumbiaweather · weather microserver firmware · CWE-923 | Высокая8,7 | — | 0,3 % | 7 янв. 2026 г. |
33Наблюдать | CVE-2024-24974Эксплойта нет | The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attackeropenvpn · openvpn · CWE-923 | Высокая7,5 | — | 9,8 % | 8 июл. 2024 г. |
33Наблюдать | CVE-2025-29986Эксплойта нет | Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulneradell · common event enabler · CWE-923 | Высокая8,3 | — | 0,3 % | 8 апр. 2025 г. |
31Наблюдать | CVE-2024-26131Эксплойта нет | Element Android Intent Redirectionelement · element · CWE-923 | Высокая7,8 | — | 0,5 % | 28 февр. 2024 г. |
30Наблюдать | CVE-2026-23664Эксплойта нет | Azure IoT Explorer Information Disclosure Vulnerabilitymicrosoft · azure iot explorer · CWE-923 | Высокая7,5 | — | 1,0 % | 10 мар. 2026 г. |
30Наблюдать | CVE-2024-34446Эксплойта нет | Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNCWE-923 | Высокая7,5 | — | 0,6 % | 3 мая 2024 г. |
30Наблюдать | CVE-2024-47490Эксплойта нет | Junos OS Evolved: ACX 7000 Series: Receipt of specific transit MPLS packets causes resources to be exhaustedjuniper · junos os evolved · CWE-923 | Высокая7,7 | — | 0,6 % | 11 окт. 2024 г. |
30Наблюдать | CVE-2026-87734Эксплойта нет | An issue was discovered in the utcp package before 0.0.6 for OCaml.ocaml · utcp · CWE-923 | Высокая7,5 | — | 0,5 % | 9 сент. 2026 г. |
30Наблюдать | CVE-2024-26013Эксплойта нет | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.fortinet · fortianalyzer · CWE-923 | Высокая7,5 | — | 0,5 % | 8 апр. 2025 г. |
30Наблюдать | CVE-2025-23178Эксплойта нет | Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpointsribbon communications · apollo 9608 · CWE-923 | Высокая7,6 | — | 0,3 % | 29 апр. 2025 г. |
30Наблюдать | CVE-2026-59841Эксплойта нет | A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 mafortinet · fortisiem · CWE-923 | Высокая7,5 | — | 0,2 % | 14 июл. 2026 г. |
30Наблюдать | CVE-2025-36180Эксплойта нет | Inadequate Pod Communication Restrictions, affects watsonx.dataibm · watsonx.data · CWE-923 | Высокая7,5 | — | 0,2 % | 30 апр. 2026 г. |
30Наблюдать | CVE-2024-47125Эксплойта нет | Improper Restriction of Communication Channel to Intended Endpoints in goTenna Progotenna · gotenna pro · CWE-923 | Высокая7,6 | — | 0,1 % | 26 сент. 2024 г. |
29Наблюдать | CVE-2026-23904Эксплойта нет | Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxyapache · kyuubi · CWE-923 | Высокая7,3 | — | 0,9 % | 29 июл. 2026 г. |
29Наблюдать | CVE-2024-43571Эксплойта нет | Sudo for Windows Spoofing Vulnerabilitymicrosoft · windows 11 24h2 · CWE-923 | Высокая7,3 | — | 0,6 % | 8 окт. 2024 г. |
29Наблюдать | CVE-2024-6222Эксплойта нет | In Docker Desktop before v4.29.0 an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passidocker · desktop · CWE-923 | Высокая7,3 | — | 0,6 % | 9 июл. 2024 г. |
29Наблюдать | CVE-2026-13608Эксплойта нет | OpenLDAP SASL authentication bypasshaxx · curl · CWE-923 | Высокая7,4 | — | 0,5 % | 6 сент. 2026 г. |
- CVE-2019-1744040В плане
PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root access
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %paloaltonetworks · pan-os20 дек. 2019 г.
- CVE-2026-6283640В плане
Azure SQL Managed Instance Elevation of Privilege Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %microsoft · azure sql managed instance6 авг. 2026 г.
- CVE-2024-4188939Наблюдать
Multiple Pimax products accept WebSocket connections from unintended endpoints.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pimax · pitool5 авг. 2024 г.
- CVE-2017-389138Наблюдать
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %blackberry · qnx software development platform14 нояб. 2017 г.
- CVE-2026-3420538Наблюдать
Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %home-assistant · home assistant operating system27 мар. 2026 г.
- CVE-2023-2807836Наблюдать
Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %dell · smartfabric os1015 февр. 2024 г.
- CVE-2022-4391636Наблюдать
IBM App Connect Enterprise Certified Container improper communications restriction
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %ibm · app connect enterprise certified container30 янв. 2025 г.
- CVE-2025-2026135Наблюдать
Cisco Integrated Management Controller Privilege Escalation Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %cisco · cisco unified computing system (managed)4 июн. 2025 г.
- CVE-2025-6193934Наблюдать
Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %columbiaweather · weather microserver firmware7 янв. 2026 г.
- CVE-2024-2497433Наблюдать
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %openvpn · openvpn8 июл. 2024 г.
- CVE-2025-2998633Наблюдать
Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnera
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %dell · common event enabler8 апр. 2025 г.
- CVE-2024-2613131Наблюдать
Element Android Intent Redirection
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %element · element28 февр. 2024 г.
- CVE-2026-2366430Наблюдать
Azure IoT Explorer Information Disclosure Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microsoft · azure iot explorer10 мар. 2026 г.
- CVE-2024-3444630Наблюдать
Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DN
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %3 мая 2024 г.
- CVE-2024-4749030Наблюдать
Junos OS Evolved: ACX 7000 Series: Receipt of specific transit MPLS packets causes resources to be exhausted
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %juniper · junos os evolved11 окт. 2024 г.
- CVE-2026-8773430Наблюдать
An issue was discovered in the utcp package before 0.0.6 for OCaml.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ocaml · utcp9 сент. 2026 г.
- CVE-2024-2601330Наблюдать
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %fortinet · fortianalyzer8 апр. 2025 г.
- CVE-2025-2317830Наблюдать
Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %ribbon communications · apollo 960829 апр. 2025 г.
- CVE-2026-5984130Наблюдать
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 ma
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %fortinet · fortisiem14 июл. 2026 г.
- CVE-2025-3618030Наблюдать
Inadequate Pod Communication Restrictions, affects watsonx.data
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · watsonx.data30 апр. 2026 г.
- CVE-2024-4712530Наблюдать
Improper Restriction of Communication Channel to Intended Endpoints in goTenna Pro
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %gotenna · gotenna pro26 сент. 2024 г.
- CVE-2026-2390429Наблюдать
Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %apache · kyuubi29 июл. 2026 г.
- CVE-2024-4357129Наблюдать
Sudo for Windows Spoofing Vulnerability
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %microsoft · windows 11 24h28 окт. 2024 г.
- CVE-2024-622229Наблюдать
In Docker Desktop before v4.29.0 an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passi
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %docker · desktop9 июл. 2024 г.
- CVE-2026-1360829Наблюдать
OpenLDAP SASL authentication bypass
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %haxx · curl6 сент. 2026 г.