VYPR

CWE-1188

Initialization of a Resource with an Insecure Default

BaseIncomplete

Description

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (345)

page 10 of 18
  • CVE-2024-32114HigMay 2, 2024
    risk 0.49cvss 8.5epss 0.07

    In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with the…

  • CVE-2022-48493HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-48492HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-1618HigMay 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which…

  • CVE-2022-40468HigSep 19, 2022
    risk 0.49cvss 7.5epss 0.02

    Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.

  • CVE-2022-1278HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.

  • CVE-2019-20470HigFeb 1, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone number, initiated by sending a specific SMS and using the…

  • CVE-2020-11489HigOct 29, 2020
    risk 0.49cvss 7.5epss 0.01

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which may lead to information disclosure.

  • CVE-2019-13393HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre-shared key. Either an attack against HTTP Basic Authentication or an attack against WPA2 could be used to determine this…

  • CVE-2010-2247HigNov 6, 2019
    risk 0.49cvss 7.5epss 0.01

    makepasswd 1.10 default settings generate insecure passwords

  • CVE-2018-15685HigAug 23, 2018
    risk 0.49cvss 8.1epss 0.10

    GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.

  • CVE-2017-6750HigJul 25, 2017
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI, aka a Static…

  • CVE-2026-55581HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.00

    mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not…

  • CVE-2026-33376HigMay 13, 2026
    risk 0.48cvss 7.4epss 0.00

    When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are…

  • CVE-2018-0263HigJun 7, 2018
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal…

  • CVE-2017-9137HigMay 21, 2017
    risk 0.48cvss 7.3epss 0.01

    Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account (a hidden user account established by the vendor). This account can be accessed via both the web interface and SSH. In the web interface, this simply grants an attacker…

  • CVE-2017-5155HigFeb 13, 2017
    risk 0.48cvss 7.3epss 0.02

    An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond…

  • CVE-2026-53507HigAug 31, 2026
    risk 0.47cvss —epss 0.00

    oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $refs in the OpenAPI spec by default (allow-external-refs: true). When an action runs on a pull…

  • CVE-2026-34780HigApr 4, 2026
    risk 0.47cvss 8.3epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the…

  • CVE-2025-48621HigDec 8, 2025
    risk 0.47cvss 7.3epss 0.00

    In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.