VYPR

CWE-420

Unprotected Alternate Channel

BaseDraft

Description

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Hierarchy (View 1000)

CVEs mapped to this weakness (37)

page 1 of 2
  • CVE-2023-20198CriKEVOct 16, 2023
    risk 0.88cvss 10.0epss 1.00

    Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two…

  • CVE-2025-54309CriKEVJul 18, 2025
    risk 0.78cvss 9.0epss 0.94

    CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

  • CVE-2025-13315CriNov 19, 2025
    risk 0.69cvss 9.8epss 0.33

    Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

  • CVE-2025-52921CriJun 23, 2025
    risk 0.64cvss 9.9epss 0.00

    In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the…

  • CVE-2024-10081CriNov 6, 2024
    risk 0.61cvss 10.0epss 0.39

    CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints other than Authentication.…

  • CVE-2026-40217HigApr 10, 2026
    risk 0.58cvss 8.8epss 0.07

    LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

  • CVE-2025-62001HigDec 18, 2025
    risk 0.57cvss 8.8epss 0.00

    BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated attacker to rename directories in a way that avoids monitoring. Fixed…

  • CVE-2025-8557HigSep 11, 2025
    risk 0.57cvss 8.8epss 0.00

    An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) network segment may be able to manipulate the local device to create an alternate…

  • CVE-2025-1095HigApr 8, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM.…

  • CVE-2023-31241HigMay 22, 2023
    risk 0.56cvss 8.6epss 0.01

    Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.

  • CVE-2025-41727HigJan 27, 2026
    risk 0.51cvss 7.8epss 0.00

    A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.

  • CVE-2023-4570HigOct 5, 2023
    risk 0.50cvss 8.8epss 0.00

    An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written…

  • CVE-2023-7266HigDec 28, 2024
    risk 0.49cvss 7.5epss 0.00

    Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been assigned a (CVE)ID:CVE-2023-7266

  • CVE-2025-59033HigSep 8, 2025
    risk 0.48cvss 7.4epss 0.00

    The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash…

  • CVE-2024-6242HigAug 1, 2024
    risk 0.48cvss epss 0.09

    A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that…

  • CVE-2025-53967HigOct 8, 2025
    risk 0.46cvss 8.0epss 0.07

    Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl command. The vulnerable endpoint fails to…

  • CVE-2024-8038HigOct 2, 2024
    risk 0.44cvss 7.9epss 0.00

    Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.

  • CVE-2023-28842MedApr 4, 2023
    risk 0.44cvss 6.8epss 0.01

    Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby is commonly referred to as…

  • CVE-2026-43505MedMay 1, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relaying of unauthenticated traffic can occur.

  • CVE-2023-52718MedDec 28, 2024
    risk 0.42cvss 6.4epss 0.00

    A connection hijacking vulnerability exists in some Huawei home routers. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-34408) This vulnerability has been assigned a (CVE)ID:CVE-2023-52718