VYPR

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints

ClassIncomplete

Description

The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-161 · CAPEC-481 · CAPEC-501 · CAPEC-697

CVEs mapped to this weakness (70)

page 4 of 4
  • CVE-2025-27769LowMar 10, 2026
    risk 0.17cvss 2.6epss 0.00

    A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized…

  • CVE-2024-39271LowFeb 12, 2025
    risk 0.17cvss 2.6epss 0.00

    Improper restriction of communication channel to intended endpoints in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software before version 23.80 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

  • CVE-2026-18655MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or…

  • CVE-2026-63226MedJul 23, 2026
    risk 0.00cvss 5.8epss 0.00

    Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other…

  • CVE-2026-8920HigJul 15, 2026
    risk 0.00cvss epss 0.00

    Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path…

  • CVE-2026-59841HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via

  • CVE-2026-57028HigJul 9, 2026
    risk 0.00cvss 7.3epss 0.00

    An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which should only be able to…

  • CVE-2026-33803MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device. Due to a wrong…

  • CVE-2025-48999HigJun 3, 2025
    risk 0.00cvss 8.8epss 0.08

    DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if…

  • CVE-2024-26131HigFeb 29, 2024
    risk 0.00cvss 8.4epss 0.00

    Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Possible impact includes making Element…