VYPR

CWE-1327

Binding to an Unrestricted IP Address

BaseIncomplete

Description

The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (22)

page 1 of 2
  • CVE-2025-61934CriOct 23, 2025
    risk 0.65cvss 10.0epss 0.01

    A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files…

  • CVE-2023-1968CriApr 28, 2023
    risk 0.65cvss 10.0epss 0.02

    Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications.

  • CVE-2025-3621CriJul 15, 2025
    risk 0.62cvss 9.6epss 0.01

    Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injection') * Use of Hard-coded…

  • CVE-2026-0481CriMay 15, 2026
    risk 0.60cvss epss 0.00

    Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability

  • CVE-2026-57123criJun 18, 2026
    risk 0.59cvss epss

    The MCP SSE server started via ToolsMCPServer.run_sse() / launch_tools_mcp_server(transport="sse") binds to 0.0.0.0 by default and builds its Starlette application with no authentication middleware and no Origin-header validation. The module mcp/mcp_security.py provides exactly…

  • CVE-2026-24015CriMar 9, 2026
    risk 0.57cvss 9.8epss 0.01

    A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.

  • CVE-2026-42503HigMay 6, 2026
    risk 0.50cvss 8.8epss 0.00

    gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0.  As a result, users might inadvertently cause gopls…

  • CVE-2023-41742HigAug 31, 2023
    risk 0.49cvss 7.5epss 0.00

    Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2025-55322HigSep 24, 2025
    risk 0.47cvss 7.3epss 0.00

    Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.

  • CVE-2026-21528MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.01

    Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2023-5398MedApr 17, 2024
    risk 0.38cvss 5.9epss 0.00

    Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. See Honeywell Security Notification for recommendations on upgrading and versioning.

  • CVE-2025-11538MedNov 13, 2025
    risk 0.37cvss 6.8epss 0.00

    A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug ) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker…

  • CVE-2026-28395MedMar 5, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as loopback addresses, allowing the relay HTTP/WS server to bind to all interfaces…

  • CVE-2024-47176MedSep 26, 2024
    risk 0.34cvss 5.3epss 0.51

    CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from…

  • CVE-2024-49384MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-49383MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-49382MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-36105MedMay 27, 2024
    risk 0.28cvss 5.3epss 0.01

    dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Prior to versions 1.6.15, 1.7.15, and 1.8.1, Binding to `INADDR_ANY (0.0.0.0)` or `IN6ADDR_ANY (::)` exposes an application on all network…

  • CVE-2022-29820LowApr 28, 2022
    risk 0.20cvss 3.0epss 0.00

    In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible

  • CVE-2026-16503CriJul 31, 2026
    risk 0.00cvss 9.1epss 0.00

    Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW…