CWE-923
Allowed-with-ReviewImproper Restriction of Communication Channel to Intended Endpoints
Abstraction: Class · Status: Incomplete
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
140 vulnerabilities reference this CWE, most recent first.
GHSA-VC7R-JRPG-M6J5
Vulnerability from github – Published: 2026-03-10 18:31 – Updated: 2026-03-10 18:31A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.
{
"affected": [],
"aliases": [
"CVE-2025-27769"
],
"database_specific": {
"cwe_ids": [
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-03-10T18:17:52Z",
"severity": "LOW"
},
"details": "A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions \u003c F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions \u003c L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.",
"id": "GHSA-vc7r-jrpg-m6j5",
"modified": "2026-03-10T18:31:18Z",
"published": "2026-03-10T18:31:18Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27769"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-126399.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-VP9H-P637-9XFW
Vulnerability from github – Published: 2024-05-03 15:30 – Updated: 2024-08-01 15:31Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged by operators of unintended DNS servers.
{
"affected": [],
"aliases": [
"CVE-2024-34446"
],
"database_specific": {
"cwe_ids": [
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-03T15:15:08Z",
"severity": "HIGH"
},
"details": "Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged by operators of unintended DNS servers.",
"id": "GHSA-vp9h-p637-9xfw",
"modified": "2024-08-01T15:31:43Z",
"published": "2024-05-03T15:30:55Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34446"
},
{
"type": "WEB",
"url": "https://github.com/mullvad/mullvadvpn-app/commit/0c39306a40f426853d617e20d596942e41091f13"
},
{
"type": "WEB",
"url": "https://github.com/mullvad/mullvadvpn-app/blob/main/CHANGELOG.md"
},
{
"type": "WEB",
"url": "https://github.com/mullvad/mullvadvpn-app/tags"
},
{
"type": "WEB",
"url": "https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android"
},
{
"type": "WEB",
"url": "https://news.ycombinator.com/item?id=40247604"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-W34Q-CM8F-9C5X
Vulnerability from github – Published: 2026-09-17 20:31 – Updated: 2026-09-17 20:31Summary
The OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, or related client certificate variables for CA pinning or mTLS get a connection that falls back to system roots and omits the env-supplied client certificate. A network attacker who can intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry.
Introduced in commit: d99c76f
Details
The affected code is in exporters/otlp/otlplog/otlploggrpc.
newConfig resolves env-based TLS configuration into cfg.tlsCfg at exporters/otlp/otlplog/otlploggrpc/config.go:106-116. The finding also identifies loadEnvTLS at config.go:451-492 as the code that builds a *tls.Config containing RootCAs and client certificates from OTEL_EXPORTER_OTLP[_LOGS]_CERTIFICATE and OTEL_EXPORTER_OTLP[_LOGS]_CLIENT_CERTIFICATE/KEY.
However, newGRPCDialOptions in exporters/otlp/otlplog/otlploggrpc/client.go:83-92 only checks cfg.gRPCCredentials and cfg.insecure. When neither is set, which is the normal env-only TLS configuration path, it uses credentials.NewTLS(nil). That default trusts the host system root CAs and contains no env-supplied client certificate. The finding evidence reports no other tlsCfg use in the package, so env-based CA pinning and mTLS settings are loaded but not enforced.
PoC
The validation artifact contains a ready-to-run test at validation-artifact.zip:./poc_env_tls_ignored_test.go and brief instructions at validation-artifact.zip:./README.md.
From a checkout of pellared/opentelemetry-go at commit d99c76f, with Go module dependencies available:
FINDING_DIR=/path/to/02-e6e2897a969c8191b260f243fbc99ebd-log-grpc-exporter-ignores-env-tls-certs-bypassing-mtls-pinning
cd /path/to/opentelemetry-go
git checkout d99c76f
tar -xOf validation-artifact.tar ./poc_env_tls_ignored_test.go > exporters/otlp/otlplog/otlploggrpc/poc_env_tls_ignored_test.go
cd exporters/otlp/otlplog/otlploggrpc
GO111MODULE=on go test -v -run TestEnvTLSIgnored -count=1
The test generates a private CA and a TLS gRPC logs server certificate signed by that CA. It sets:
OTEL_EXPORTER_OTLP_LOGS_ENDPOINT=https://127.0.0.1:<test-port>
OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE=<temp-dir>/ca.pem
Expected output includes an unknown authority failure for the first export call even though the env certificate points to the server CA, followed by a passing test after the same cfg.tlsCfg is explicitly wired through WithTLSCredentials:
=== RUN TestEnvTLSIgnored
poc_env_tls_ignored_test.go:...: export error (expected due to ignored tlsCfg): ... x509: certificate signed by unknown authority
--- PASS: TestEnvTLSIgnored
PASS
This demonstrates that the env CA is parsed into cfg.tlsCfg but ignored by the default gRPC dial path.
Impact
This is improper TLS certificate validation and endpoint authentication caused by ignoring configured trust material. Users of the OTLP log gRPC exporter who configure TLS, CA pinning, or mTLS through environment variables are impacted when they do not also supply explicit WithTLSCredentials. TLS still occurs with system roots, but the intended private CA pinning and client certificate authentication are bypassed. An attacker with a suitable network position and a system-trusted certificate for the collector endpoint can intercept or tamper with log telemetry that operators expected to be protected by the configured CA or mTLS policy.
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.21.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-81871"
],
"database_specific": {
"cwe_ids": [
"CWE-295",
"CWE-923"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T20:31:09Z",
"nvd_published_at": "2026-09-16T21:17:22Z",
"severity": "MODERATE"
},
"details": "### Summary\n\nThe OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on `OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE`, `OTEL_EXPORTER_OTLP_CERTIFICATE`, or related client certificate variables for CA pinning or mTLS get a connection that falls back to system roots and omits the env-supplied client certificate. A network attacker who can intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. \n\nIntroduced in commit: d99c76f\n\n### Details\n\nThe affected code is in `exporters/otlp/otlplog/otlploggrpc`.\n\n`newConfig` resolves env-based TLS configuration into `cfg.tlsCfg` at `exporters/otlp/otlplog/otlploggrpc/config.go:106-116`. The finding also identifies `loadEnvTLS` at `config.go:451-492` as the code that builds a `*tls.Config` containing `RootCAs` and client certificates from `OTEL_EXPORTER_OTLP[_LOGS]_CERTIFICATE` and `OTEL_EXPORTER_OTLP[_LOGS]_CLIENT_CERTIFICATE`/`KEY`.\n\nHowever, `newGRPCDialOptions` in `exporters/otlp/otlplog/otlploggrpc/client.go:83-92` only checks `cfg.gRPCCredentials` and `cfg.insecure`. When neither is set, which is the normal env-only TLS configuration path, it uses `credentials.NewTLS(nil)`. That default trusts the host system root CAs and contains no env-supplied client certificate. The finding evidence reports no other `tlsCfg` use in the package, so env-based CA pinning and mTLS settings are loaded but not enforced.\n\n### PoC\n\n[validation-artifact.zip](https://github.com/user-attachments/files/27493589/validation-artifact.zip)\n\n\nThe validation artifact contains a ready-to-run test at `validation-artifact.zip:./poc_env_tls_ignored_test.go` and brief instructions at `validation-artifact.zip:./README.md`.\n\nFrom a checkout of `pellared/opentelemetry-go` at commit `d99c76f`, with Go module dependencies available:\n\n```sh\nFINDING_DIR=/path/to/02-e6e2897a969c8191b260f243fbc99ebd-log-grpc-exporter-ignores-env-tls-certs-bypassing-mtls-pinning\ncd /path/to/opentelemetry-go\ngit checkout d99c76f\ntar -xOf validation-artifact.tar ./poc_env_tls_ignored_test.go \u003e exporters/otlp/otlplog/otlploggrpc/poc_env_tls_ignored_test.go\ncd exporters/otlp/otlplog/otlploggrpc\nGO111MODULE=on go test -v -run TestEnvTLSIgnored -count=1\n```\n\nThe test generates a private CA and a TLS gRPC logs server certificate signed by that CA. It sets:\n\n```sh\nOTEL_EXPORTER_OTLP_LOGS_ENDPOINT=https://127.0.0.1:\u003ctest-port\u003e\nOTEL_EXPORTER_OTLP_LOGS_CERTIFICATE=\u003ctemp-dir\u003e/ca.pem\n```\n\nExpected output includes an `unknown authority` failure for the first export call even though the env certificate points to the server CA, followed by a passing test after the same `cfg.tlsCfg` is explicitly wired through `WithTLSCredentials`:\n\n```text\n=== RUN TestEnvTLSIgnored\n poc_env_tls_ignored_test.go:...: export error (expected due to ignored tlsCfg): ... x509: certificate signed by unknown authority\n--- PASS: TestEnvTLSIgnored\nPASS\n```\n\nThis demonstrates that the env CA is parsed into `cfg.tlsCfg` but ignored by the default gRPC dial path.\n\n### Impact\n\nThis is improper TLS certificate validation and endpoint authentication caused by ignoring configured trust material. Users of the OTLP log gRPC exporter who configure TLS, CA pinning, or mTLS through environment variables are impacted when they do not also supply explicit `WithTLSCredentials`. TLS still occurs with system roots, but the intended private CA pinning and client certificate authentication are bypassed. An attacker with a suitable network position and a system-trusted certificate for the collector endpoint can intercept or tamper with log telemetry that operators expected to be protected by the configured CA or mTLS policy.",
"id": "GHSA-w34q-cm8f-9c5x",
"modified": "2026-09-17T20:31:09Z",
"published": "2026-09-17T20:31:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81871"
},
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c"
},
{
"type": "PACKAGE",
"url": "https://github.com/open-telemetry/opentelemetry-go"
},
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning"
}
GHSA-W3GP-GPRX-5VJ8
Vulnerability from github – Published: 2024-09-26 18:31 – Updated: 2024-10-04 21:31The goTenna Pro series does not authenticate public keys which allows an unauthenticated attacker to intercept and manipulate messages.
{
"affected": [],
"aliases": [
"CVE-2024-47125"
],
"database_specific": {
"cwe_ids": [
"CWE-287",
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-26T18:15:09Z",
"severity": "HIGH"
},
"details": "The goTenna Pro series does not authenticate public keys which allows an unauthenticated attacker to intercept and manipulate messages.",
"id": "GHSA-w3gp-gprx-5vj8",
"modified": "2024-10-04T21:31:28Z",
"published": "2024-09-26T18:31:45Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47125"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-W762-77XF-823W
Vulnerability from github – Published: 2024-08-05 06:30 – Updated: 2024-08-07 21:31Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.
{
"affected": [],
"aliases": [
"CVE-2024-41889"
],
"database_specific": {
"cwe_ids": [
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-05T05:15:39Z",
"severity": "HIGH"
},
"details": "Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.",
"id": "GHSA-w762-77xf-823w",
"modified": "2024-08-07T21:31:43Z",
"published": "2024-08-05T06:30:37Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41889"
},
{
"type": "WEB",
"url": "https://github.com/OpenMAR/PiTool"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN50850706"
},
{
"type": "WEB",
"url": "https://pimax.com/pages/downloads-manuals"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-WCVF-3X75-J4C6
Vulnerability from github – Published: 2026-06-23 06:30 – Updated: 2026-08-25 12:31A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
{
"affected": [],
"aliases": [
"CVE-2026-55655"
],
"database_specific": {
"cwe_ids": [
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-06-23T04:17:40Z",
"severity": "MODERATE"
},
"details": "A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.",
"id": "GHSA-wcvf-3x75-j4c6",
"modified": "2026-08-25T12:31:20Z",
"published": "2026-06-23T06:30:41Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55655"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:36759"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:47755"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:47756"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:47757"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54387"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:58981"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2026-55655"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2462250"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-WH8R-HXHG-W5G2
Vulnerability from github – Published: 2023-06-23 18:30 – Updated: 2024-04-04 05:07NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and loss of integrity.
{
"affected": [],
"aliases": [
"CVE-2023-25515"
],
"database_specific": {
"cwe_ids": [
"CWE-822",
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-23T18:15:10Z",
"severity": "HIGH"
},
"details": "\nNVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and loss of integrity. \n\n",
"id": "GHSA-wh8r-hxhg-w5g2",
"modified": "2024-04-04T05:07:09Z",
"published": "2023-06-23T18:30:23Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25515"
},
{
"type": "WEB",
"url": "https://https://nvidia.custhelp.com/app/answers/detail/a_id/5466"
},
{
"type": "WEB",
"url": "https://https://nvidia.custhelp.com/app/answers/detail/a_id/5468"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-X279-FQQW-2JVV
Vulnerability from github – Published: 2025-01-28 03:31 – Updated: 2025-01-28 03:31IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.
{
"affected": [],
"aliases": [
"CVE-2024-22315"
],
"database_specific": {
"cwe_ids": [
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-28T02:15:28Z",
"severity": "MODERATE"
},
"details": "IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.",
"id": "GHSA-x279-fqqw-2jvv",
"modified": "2025-01-28T03:31:14Z",
"published": "2025-01-28T03:31:14Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22315"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7179168"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-X7QM-J22R-CGCW
Vulnerability from github – Published: 2026-09-30 21:32 – Updated: 2026-10-01 21:32Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
{
"affected": [],
"aliases": [
"CVE-2026-92173"
],
"database_specific": {
"cwe_ids": [
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-30T21:17:17Z",
"severity": "CRITICAL"
},
"details": "Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.",
"id": "GHSA-x7qm-j22r-cgcw",
"modified": "2026-10-01T21:32:48Z",
"published": "2026-09-30T21:32:13Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92173"
},
{
"type": "WEB",
"url": "https://www.facebook.com/security/advisories/cve-2026-92173"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-XC4G-8C26-VCMF
Vulnerability from github – Published: 2026-07-10 00:31 – Updated: 2026-07-10 00:31An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.
Due to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent processing ingress packets.
This issue affects Junos OS Evolved:
- all versions before 23.2R2-S7-EVO,
- 23.4 versions before 23.4R2-S8-EVO,
- 24.2 versions before 24.2R2-S5-EVO,
- 24.4 versions before 24.4R2-S4-EVO,
- 25.2 versions before 25.2R2-S1-EVO,
- 25.4 versions before 25.4R1-S2-EVO.
{
"affected": [],
"aliases": [
"CVE-2026-33803"
],
"database_specific": {
"cwe_ids": [
"CWE-923"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-09T22:17:03Z",
"severity": "MODERATE"
},
"details": "An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.\n\n\nDue to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent processing ingress packets.\n\nThis issue affects Junos OS Evolved:\n\n\n * all versions before 23.2R2-S7-EVO,\n * 23.4 versions before 23.4R2-S8-EVO,\n * 24.2 versions before 24.2R2-S5-EVO,\n * 24.4 versions before 24.4R2-S4-EVO,\n * 25.2 versions before 25.2R2-S1-EVO,\n * 25.4 versions before 25.4R1-S2-EVO.",
"id": "GHSA-xc4g-8c26-vcmf",
"modified": "2026-07-10T00:31:25Z",
"published": "2026-07-10T00:31:25Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33803"
},
{
"type": "WEB",
"url": "https://supportportal.juniper.net/JSA110078"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X",
"type": "CVSS_V4"
}
]
}
No mitigation information available for this CWE.
CAPEC-161: Infrastructure Manipulation
An attacker exploits characteristics of the infrastructure of a network entity in order to perpetrate attacks or information gathering on network objects or effect a change in the ordinary information flow between network objects. Most often, this involves manipulation of the routing of network messages so, instead of arriving at their proper destination, they are directed towards an entity of the attackers' choosing, usually a server controlled by the attacker. The victim is often unaware that their messages are not being processed correctly. For example, a targeted client may believe they are connecting to their own bank but, in fact, be connecting to a Pharming site controlled by the attacker which then collects the user's login information in order to hijack the actual bank account.
CAPEC-481: Contradictory Destinations in Traffic Routing Schemes
Adversaries can provide contradictory destinations when sending messages. Traffic is routed in networks using the domain names in various headers available at different levels of the OSI model. In a Content Delivery Network (CDN) multiple domains might be available, and if there are contradictory domain names provided it is possible to route traffic to an inappropriate destination. The technique, called Domain Fronting, involves using different domain names in the SNI field of the TLS header and the Host field of the HTTP header. An alternative technique, called Domainless Fronting, is similar, but the SNI field is left blank.
CAPEC-501: Android Activity Hijack
An adversary intercepts an implicit intent sent to launch a Android-based trusted activity and instead launches a counterfeit activity in its place. The malicious activity is then used to mimic the trusted activity's user interface and prompt the target to enter sensitive data as if they were interacting with the trusted activity.
CAPEC-697: DHCP Spoofing
An adversary masquerades as a legitimate Dynamic Host Configuration Protocol (DHCP) server by spoofing DHCP traffic, with the goal of redirecting network traffic or denying service to DHCP.