VYPR

CWE-1188

Initialization of a Resource with an Insecure Default

BaseIncomplete

Description

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (330)

page 11 of 17
  • CVE-2025-66416HigDec 2, 2025
    risk 0.46cvss 8.1epss 0.01

    The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP…

  • CVE-2025-66414HigDec 2, 2025
    risk 0.46cvss 8.1epss 0.01

    MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on…

  • CVE-2023-3453HigAug 23, 2023
    risk 0.46cvss 7.1epss 0.00

    ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the configuration of the device or cause a denial-of-service condition.

  • CVE-2026-53660higAug 14, 2026
    risk 0.45cvss epss

    ## Summary **Description** An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the `iPlanetDirectoryPro` SSO cookie with `HttpOnly=false`. Also, the `iPlanetDirectoryPro` SSO cookie is used as a CSRF token in OAuth/OIDC…

  • CVE-2026-46619higJun 26, 2026
    risk 0.45cvss epss

    ## Summary **Description** An LDAP Injection (CWE-90) vulnerability in the MSISDN authentication module allows an unauthenticated, remote attacker to obtain an arbitrary OpenAM session without a password in the default trusted gateway configuration. This impacts OpenAM…

  • CVE-2025-2442MedApr 9, 2025
    risk 0.44cvss 6.8epss 0.00

    CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unauthorized access which could result in the loss of confidentially, integrity and availability when a malicious user, having physical access, sets the radio to…

  • CVE-2024-48122MedJan 15, 2025
    risk 0.44cvss 6.7epss 0.00

    Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileges to escalate to root-level privileges.

  • CVE-2023-48733MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

  • CVE-2021-0114MedAug 16, 2021
    risk 0.44cvss 6.7epss 0.00

    Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0144MedJul 14, 2021
    risk 0.44cvss 6.7epss 0.00

    Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2020-11915MedFeb 8, 2021
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to the webserver, it is possible to enable the telnet interface on the device. The telnet interface can then be used to obtain access to the…

  • CVE-2020-8705MedNov 12, 2020
    risk 0.44cvss 6.8epss 0.01

    Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400,…

  • CVE-2026-44338HigMay 8, 2026
    risk 0.43cvss 7.3epss 0.29

    PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured…

  • CVE-2026-43527HigMay 5, 2026
    risk 0.43cvss 7.7epss 0.00

    OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows private-network navigation by default. Attackers can exploit this misconfiguration to access internal services or metadata endpoints through browser-driven requests.

  • CVE-2022-46831MedDec 8, 2022
    risk 0.43cvss 6.6epss 0.00

    In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.

  • CVE-2021-0468MedApr 13, 2021
    risk 0.43cvss 6.6epss 0.00

    In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is needed for…

  • CVE-2018-10989MedMay 14, 2018
    risk 0.43cvss 6.6epss 0.01

    Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0.1 connection, which might allow remote attackers to bypass intended access…

  • CVE-2026-54066HigJun 24, 2026
    risk 0.42cvss 7.5epss 0.02

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route but the identical root cause remains in the /assets/*path route. In publish mode (anonymous…

  • CVE-2026-50519MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.01

    Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-9262MedJun 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier