CWE-940
CWE-940 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-940, highest CVSS first.
- HIGH 7.2CVE-2026-102117public PoC
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of th…
- UNSCOREDCVE-2026-59786
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulti…
- UNSCOREDCVE-2026-102511
Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker…