CWE-1125Base

Excessive Attack Surface

Incomplete in the CWE catalog · 5 CVEs mapped

5
CVEs mapped
9.6
Median CVSS
What it is

The product has an attack surface whose quantitative

measurement exceeds a desirable maximum.

Recent examples
9.6cvss
CVE-2024-5386

Account Hijacking via Password Reset Token Leak in lunary-ai/lunary

🚨 A 'viewer' role user can snag a password reset token, turning them into an account hijacking ninja! 🔥 Imagine a library where a lowly book reader can somehow borrow the keys to the restricted sections just by asking the librarian nicely. That's what this vulnerability does—it lets someone with minimal privileges access the secrets of other users' accounts without a second thought! With this vulnerability, an attacker could gain full control over another user's account, compromising sensitive information and potentially wreaking havoc. It’s like handing a thief the keys to the kingdom—once they’re in, they can change passwords, access private data, or impersonate the victim. The fallout? Absolutely devastating!

CRITICAL
1%
epss
8.3cvss
CVE-2023-49722

Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network

Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.

HIGHno explanation yet
0%
epss
4.0cvss
CVE-2023-0435

Excessive Attack Surface in pyload/pyload

⚠️ It turns out there’s an oversized door in the GitHub repository for pyload/pyload that could let unwanted guests in before version 0.5.0b3.dev41! Think of it as a hotel with a lobby that’s way too big—anyone might wander in without being noticed. An excessive attack surface means there are more ways for potentially harmful traffic to enter than there should be! If left unaddressed, this vulnerability could allow an attacker to exploit unnecessary entry points, leading to unauthorized access or manipulation of the application. While it’s not classified as critical, keeping it in check is essential to maintain the overall security posture of your service.

MEDIUM
1%
epss
The record
Technical detail
CWE ID
CWE-1125
Abstraction
Base
Structure
Simple
Status
Incomplete
References (2)