VYPR

CWE-642

External Control of Critical State Data

ClassDraftLikelihood: High

Description

The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-31

CVEs mapped to this weakness (17)

  • CVE-2020-27872HigFeb 4, 2021
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on…

  • CVE-2018-15382HigOct 5, 2018
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing key that is present in all Cisco HyperFlex systems. An attacker could exploit this vulnerability by…

  • CVE-2019-9496HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.05

    An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd…

  • CVE-2023-0575HigFeb 9, 2023
    risk 0.47cvss 7.2epss 0.01

    External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege…

  • CVE-2024-22387MedJul 11, 2024
    risk 0.44cvss 6.8epss 0.00

    External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated user to modify device I/O connections leading to unexpected behavior that in some circumstances could compromise site physical security…

  • CVE-2022-22154MedJan 19, 2022
    risk 0.44cvss 6.8epss 0.00

    In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attacker who is able to make physical changes to the cabling of the device to cause a denial of service…

  • CVE-2020-26186MedJan 8, 2021
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management…

  • CVE-2026-29146HigApr 9, 2026
    risk 0.42cvss 7.5epss 0.06

    Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through…

  • CVE-2024-8754MedSep 12, 2024
    risk 0.42cvss 6.4epss 0.00

    An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT…

  • CVE-2017-0928MedJun 4, 2018
    risk 0.40cvss 6.1epss 0.01

    html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.

  • CVE-2025-49090HigOct 2, 2025
    risk 0.39cvss 7.1epss 0.00

    The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.

  • CVE-2022-32859MedNov 1, 2022
    risk 0.34cvss 5.3epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted contacts may still appear in spotlight search results.

  • CVE-2025-26787MedDec 22, 2025
    risk 0.31cvss 4.7epss 0.00

    An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user with a valid and trusted…

  • CVE-2020-1976MedFeb 12, 2020
    risk 0.31cvss 4.7epss 0.00

    A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of GlobalProtect 5.0 on Mac OS.

  • CVE-2025-54566MedJul 25, 2025
    risk 0.27cvss 4.2epss 0.00

    hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

  • CVE-2026-35659MedApr 10, 2026
    risk 0.23cvss 4.6epss 0.00

    OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could influence CLI routing even when actual service resolution failed. Attackers can exploit unresolved hints to steer routing decisions to unintended targets by…

  • CVE-2024-58265LowJul 27, 2025
    risk 0.13cvss 3.1epss 0.00

    The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.