VYPR

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints

ClassIncomplete

Description

The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-161 · CAPEC-481 · CAPEC-501 · CAPEC-697

CVEs mapped to this weakness (70)

page 3 of 4
  • CVE-2025-31144MedApr 28, 2025
    risk 0.38cvss 5.8epss 0.00

    Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker may attempt to log in to an arbitrary host via Windows system where the product is running.

  • CVE-2026-12539MedJun 18, 2026
    risk 0.37cvss epss 0.00

    Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a…

  • CVE-2026-12039MedJun 18, 2026
    risk 0.37cvss epss 0.00

    Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwards any queried name to the host resolver whenever the network is internet-connected, without consulting the policy. A workload…

  • CVE-2024-43571MedOct 8, 2024
    risk 0.36cvss 5.6epss 0.01

    Sudo for Windows Spoofing Vulnerability

  • CVE-2025-36145MedMay 26, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.

  • CVE-2023-44195MedOct 13, 2023
    risk 0.35cvss 5.4epss 0.00

    An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the NetworkStack agent daemon (nsagentd) of Juniper Networks Junos OS Evolved allows an unauthenticated network based attacker to cause limited impact to the availability of the system. If…

  • CVE-2022-2663MedSep 1, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.

  • CVE-2025-36180MedApr 30, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.

  • CVE-2021-32635MedMay 28, 2021
    risk 0.34cvss 6.3epss 0.01

    Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the…

  • CVE-2026-55655MedJun 23, 2026
    risk 0.33cvss 5.0epss 0.00

    A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A…

  • CVE-2026-22726MedMay 1, 2026
    risk 0.33cvss 5.0epss 0.00

    Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on…

  • CVE-2025-36438MedMar 25, 2026
    risk 0.33cvss 5.1epss 0.00

    IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restriction of channel communication to intended endpoints.

  • CVE-2023-29108MedApr 11, 2023
    risk 0.33cvss 5.0epss 0.00

    The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable access to backend applications from unwanted sources.

  • CVE-2022-2835MedMar 3, 2023
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of ..svc.

  • CVE-2025-32886MedMay 1, 2025
    risk 0.26cvss 4.0epss 0.00

    An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data.

  • CVE-2024-22315MedJan 28, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.

  • CVE-2021-32004LowNov 22, 2021
    risk 0.24cvss 3.7epss 0.01

    This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.

  • CVE-2022-30729LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.

  • CVE-2025-22251LowJun 10, 2025
    risk 0.20cvss 3.1epss 0.00

    An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP…

  • CVE-2022-38125LowApr 19, 2023
    risk 0.19cvss 2.9epss 0.00

    Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client.