Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (f
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authe
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to versio
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacke
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A re
An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora.
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.
Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability
VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malic
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port for
IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could
IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow a
IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restrictio
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules.
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding
A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC
Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network
Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa
Frequently Asked Questions
What is CWE-923?
CWE-923 (CWE-923) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-923?
There are 25 CVE records associated with CWE-923 in our database. Of these, 1 are critical severity, 9 are high severity, and 11 are medium severity.
How can I protect against CWE-923 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-923 using AI-powered security agents.
Detect CWE-923 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-923 vulnerabilities across your infrastructure.
Get Started