CWE-412— Unrestricted Externally Accessible Lock
The product properly checks for the existence of a lock, but the lock can be externally controlled or influenced by an actor that is outside of the intended sphere of control.— MITRE CWE catalog
6 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-412page 1 of 1
- CVE-2019-11485LOWCVSS 3.3EG 3.32020-02-08
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
- CVE-2019-18269CRITICALCVSS 9.8EG 9.82019-12-16
Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.
- CVE-2023-22318HIGHCVSS 7.5EG 7.52023-05-15
Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5.
- CVE-2023-38505HIGHCVSS 7.5EG 7.52023-07-27
DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to be in process at a given moment. Once a TCP connection is established in HTTPS mode, it will assume that it should be w…
- CVE-2026-25612MEDIUMCVSS 6.5EG 6.52026-02-10
The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability betw…
- CVE-2026-62426HIGHCVSS 8.8EG 8.82026-07-28
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore do…
Map vulnerabilities like CWE-412 to your infrastructure
EchelonGraph correlates every CVE — across CWE-412 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →