CWE-1039Class

Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
5.8
Median CVSS
What it is

The product uses an automated mechanism such as machine learning to recognize complex data inputs (e.g. image or audio) as a particular concept or category, but it does not properly detect or handle inputs that have been modified or constructed in a way that causes the mechanism to detect a different, incorrect concept.

Recent examples
9.3cvss
CVE-2025-3578

Adversarial Input Handling Vulnerability in AiDex

A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify existing users in the application, list credentials of users in production or development environments. In addition, it would be possible to cause bugs that would result in the exfiltration of sensitive information, such as details about the software or internal system paths. These actions could be carried out through the misuse of LLM Prompt (chatbot) technology, via the /api/<string-chat>/message endpoint, by manipulating the contents of the ‘content’ parameter.

CRITICALno explanation yet
0%
epss
5.1cvss
CVE-2025-26644

Windows Hello Spoofing Vulnerability

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

MEDIUMno explanation yet
1%
epss
5.8cvss
CVE-2023-20071

CVE-2023-20071 - MEDIUM Severity Vulnerability

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.

MEDIUMno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-1039
Abstraction
Class
Structure
Simple
Status
Incomplete
References (5)