CWE-923— Improper Restriction of Communication Channel to Intended Endpoints
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.— MITRE CWE catalog
82 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-923page 1 of 2
- CVE-2026-62836CRITICALCVSS 10.0EG 10.02026-08-06
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
- CVE-2019-17440CRITICALCVSS 10.0EG 10.02019-12-20
Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issu…
- CVE-2025-46566CRITICALCVSS 9.8EG 9.82025-05-01
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.9.
- CVE-2024-41889CRITICALCVSS 9.8EG 9.82024-08-05
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.
- CVE-2026-34205CRITICALCVSS 9.6EG 9.62026-03-27
Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge…
- CVE-2017-3891CRITICALCVSS 9.6EG 9.62017-11-14
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to acc…
- CVE-2026-101891CRITICALCVSS 9.3EG 9.32026-09-28
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
- CVE-2026-92173CRITICALCVSS 9.1EG 9.12026-09-30
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. Tha…
- CVE-2023-28078CRITICALCVSS 9.1EG 9.12024-02-15
Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a po…
- CVE-2021-38487CRITICALCVSS 8.2EG 9.12022-05-05
RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service…
- CVE-2026-86345CRITICALCVSS 9.0EG 9.02026-10-01
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS…
- CVE-2026-92172HIGHCVSS 8.8EG 8.82026-09-30
Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSH…
- CVE-2025-20261HIGHCVSS 8.8EG 8.82025-06-04
A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal se…
- CVE-2025-48999HIGHCVSS 8.8EG 8.82025-06-03
DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement…
- CVE-2025-61939HIGHCVSS 4.4EG 8.82026-01-07
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS resp…
- CVE-2026-78501HIGHCVSS 8.6EG 8.62026-09-17
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
- CVE-2026-8920HIGHCVSS 8.5EG 8.52026-07-15
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file …
- CVE-2024-26131HIGHCVSS 8.4EG 8.42024-02-29
Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Po…
- CVE-2025-29986HIGHCVSS 8.3EG 8.32025-04-08
Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Common Anti-Virus Agent (CAVA). An unauthenticated attacker with remote access could …
- CVE-2025-12357HIGHCVSS 6.3EG 8.32025-10-31
By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. Th…
- CVE-2026-96454HIGHCVSS 8.2EG 8.22026-09-23
Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they hand native functionality to untrusted web content. The first is in src-t…
- CVE-2024-47490HIGHCVSS 8.2EG 8.22024-10-11
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network based attacker to cause …
- CVE-2024-47125HIGHCVSS 8.1EG 8.12024-09-26
The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to the current release for enhanced encryption protocols.
- CVE-2018-10596HIGHCVSS 7.1EG 8.02018-07-03
Medtronic 2090 CareLink Programmer uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affected products initial…
- CVE-2023-25515HIGHCVSS 7.8EG 7.82023-06-23
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, which may lead to code execution, denial of service, escalation of privileges, data tampering, or information disclosure…
- CVE-2025-23178HIGHCVSS 7.6EG 7.62025-04-29
CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
- CVE-2026-87734HIGHCVSS 7.5EG 7.52026-09-09
An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.
- CVE-2026-59841HIGHCVSS 7.5EG 7.52026-07-14
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>
- CVE-2025-36180HIGHCVSS 7.5EG 7.52026-04-30
IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.
- CVE-2026-23664HIGHCVSS 7.5EG 7.52026-03-10
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- CVE-2024-26013HIGHCVSS 7.5EG 7.52025-04-08
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet Fort…
- CVE-2024-24974HIGHCVSS 7.5EG 7.52024-07-08
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.
- CVE-2024-34446HIGHCVSS 7.5EG 7.52024-05-03
Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive D…
- CVE-2025-48807HIGHCVSS 6.7EG 7.52025-08-12
Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
- CVE-2026-13608HIGHCVSS 7.4EG 7.42026-09-06
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a pr…
- CVE-2026-23904HIGHCVSS 7.3EG 7.32026-07-29
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachab…
- CVE-2026-57028HIGHCVSS 7.3EG 7.32026-07-09
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, …
- CVE-2023-28971HIGHCVSS 7.2EG 7.22023-04-17
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the timescaledb feature of Juniper Networks Paragon Active Assurance (PAA) (Formerly Netrounds) allows an attacker to bypass existing firewall rules an…
- CVE-2025-35978HIGHCVSS 7.1EG 7.12025-06-12
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary r…
- CVE-2023-25518HIGHCVSS 7.1EG 7.12023-06-23
NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of …
- CVE-2025-49734HIGHCVSS 7.0EG 7.02025-09-09
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
- CVE-2024-6222HIGHCVSS 7.0EG 7.02024-07-09
In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 htt…
- CVE-2025-62843MEDIUMCVSS 6.8EG 6.82026-03-20
An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended…
- CVE-2022-43916MEDIUMCVSS 6.8EG 6.82025-01-30
IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, and 12.7 Pods do not restrict network egress for Pods th…
- CVE-2026-18655MEDIUMCVSS 6.5EG 6.52026-08-03
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ…
- CVE-2026-33803MEDIUMCVSS 6.5EG 6.52026-07-09
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact t…
- CVE-2024-39537MEDIUMCVSS 6.5EG 6.52024-07-11
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and av…
- CVE-2026-81871MEDIUMCVSS 6.3EG 6.32026-09-16
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate e…
- CVE-2026-90461MEDIUMCVSS 6.3EG 6.32026-09-11
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
- CVE-2024-36252MEDIUMCVSS 6.3EG 6.32024-06-19
Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is inst…
Map vulnerabilities like CWE-923 to your infrastructure
EchelonGraph correlates every CVE — across CWE-923 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →