Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirem
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, a
A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 all
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits inst
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks
Frequently Asked Questions
What is CWE-308?
CWE-308 (CWE-308) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-308?
There are 7 CVE records associated with CWE-308 in our database. Of these, 1 are critical severity, 2 are high severity, and 2 are medium severity.
How can I protect against CWE-308 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-308 using AI-powered security agents.
Detect CWE-308 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-308 vulnerabilities across your infrastructure.
Get Started