CWE-446Class

UI Discrepancy for Security Feature

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
5.9
Median CVSS
What it is

The user interface does not correctly enable or configure a security feature, but the interface provides feedback that causes the user to believe that the feature is in a secure state.

Recent examples
5.9cvss
CVE-2025-8353

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated…

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.

MEDIUMno explanation yet
0%
epss
8.6cvss
CVE-2025-52983

Junos OS: After removing ssh public key authentication root can still log in

A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to access the device. On VM Host Routing Engines (RE), even if the configured public key for root has been removed, remote users which are in possession of the corresponding private key can still log in as root. This issue affects Junos OS: * all versions before 22.2R3-S7, * 22.4 versions before 22.4R3-S5, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S3, * 24.2 versions before 24.2R1-S2, 24.2R2.

HIGHno explanation yet
1%
epss
3.7cvss
CVE-2023-1768

Symmetric agent data encryption fails silently

Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.

LOWno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-446
Abstraction
Class
Structure
Simple
Status
Incomplete