CWE-419: Unprotected Primary Channel
The product uses a primary channel for administration or restricted functionality, but it does not properly protect the channel.
11 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-24030 — Envoy Admin Interface Exposed through prometheus metrics endpoint
- CVE-2025-31964 — HCL BigFix IVR is impacted by an improper service binding configuration
Recently published
- CVE-2025-31964 — HCL BigFix IVR is impacted by an improper service binding configuration
- CVE-2025-24030 — Envoy Admin Interface Exposed through prometheus metrics endpoint