VYPR

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints

ClassIncomplete

Description

The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-161 · CAPEC-481 · CAPEC-501 · CAPEC-697

CVEs mapped to this weakness (70)

page 2 of 4
  • CVE-2023-28971HigApr 17, 2023
    risk 0.47cvss 7.2epss 0.00

    An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the timescaledb feature of Juniper Networks Paragon Active Assurance (PAA) (Formerly Netrounds) allows an attacker to bypass existing firewall rules and limitations used to restrict internal…

  • CVE-2025-49734HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-35978HigJun 12, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or…

  • CVE-2024-6222HigJul 9, 2024
    risk 0.46cvss 7.0epss 0.01

    In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/desktop/release-note…

  • CVE-2023-25518HigJun 23, 2023
    risk 0.46cvss 7.1epss 0.00

    NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of this vulnerability may lead to code…

  • CVE-2018-10596HigJul 3, 2018
    risk 0.46cvss 7.1epss 0.01

    Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affected products initially establish an encapsulated IP-based…

  • CVE-2025-62843MedMar 20, 2026
    risk 0.44cvss 6.8epss 0.00

    An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have…

  • CVE-2025-48807MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.

  • CVE-2022-43916MedJan 30, 2025
    risk 0.44cvss 6.8epss 0.00

    IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, and 12.7 Pods do not restrict network egress for Pods that are used for internal infrastructure.

  • CVE-2026-32318HigMar 20, 2026
    risk 0.42cvss 7.6epss 0.00

    Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key…

  • CVE-2026-32317HigMar 20, 2026
    risk 0.42cvss 7.6epss 0.00

    Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key…

  • CVE-2026-32303HigMar 20, 2026
    risk 0.42cvss 7.6epss 0.00

    Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix,…

  • CVE-2024-39537MedJul 11, 2024
    risk 0.42cvss 6.5epss 0.00

    An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due…

  • CVE-2024-34446HigMay 3, 2024
    risk 0.42cvss 7.5epss 0.01

    Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged…

  • CVE-2025-12357MedOct 31, 2025
    risk 0.41cvss 6.3epss 0.00

    By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable …

  • CVE-2024-36252MedJun 19, 2024
    risk 0.41cvss 6.3epss 0.00

    Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.

  • CVE-2025-33176MedNov 4, 2025
    risk 0.40cvss 6.2epss 0.00

    NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adjacent network. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, and information…

  • CVE-2022-2837MedMar 3, 2023
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.

  • CVE-2026-22715MedFeb 26, 2026
    risk 0.38cvss 5.9epss 0.00

    VMWare Workstation and Fusion contain a logic flaw in the management of network packets.  Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's.  Resolution: To…

  • CVE-2025-58742MedJan 20, 2026
    risk 0.38cvss 5.9epss 0.00

    Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect…