CWE-923
68 CVEs • Abstraction: Class
Improper Restriction of Communication Channel to Intended Endpoints
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
CVEs (68)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Sep 1, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with n...Show more |
Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner. |
1Rti 3Connext Dds Micro Connext ProfessionalConnext SecureJun 17, 2026 May 5, 2022 8.8 HIGH· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in...Show more |
1Secomea 1Gatemanager 8250 Firmware Jun 17, 2026 Nov 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning. |
Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI wi...Show more |
Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access t...Show more |
1Medtronic 12090 Carelink Programmer Firmware May 22, 2025 Jul 3, 2018 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affect...Show more |
1Blackberry 1Qnx Software Development Platform May 13, 2026 Nov 14, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow...Show more |