CWE-670
CWE-670 · 4 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-670, highest CVSS first.
- MEDIUM 6.5CVE-2026-102124public PoC
A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a cont…
- MEDIUM 6.5CVE-2026-73468
A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.
- MEDIUM 5.9CVE-2026-102110public PoC
An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged…
- UNSCOREDCVE-2026-92932public PoC
In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] && strpos($input, 'http:…