OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Eng
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on net
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerabili
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(t
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,
The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the ris
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma
For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec
The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of nu
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar
Frequently Asked Questions
What is CWE-1391?
CWE-1391 (CWE-1391) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1391?
There are 17 CVE records associated with CWE-1391 in our database. Of these, 5 are critical severity, 2 are high severity, and 3 are medium severity.
How can I protect against CWE-1391 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1391 using AI-powered security agents.
Detect CWE-1391 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1391 vulnerabilities across your infrastructure.
Get Started