CWE-671: Lack of Administrator Control over Security
The product uses security features in a way that prevents the product's administrator from tailoring security settings to reflect the environment in which the product is being used. This introduces resultant weaknesses or prevents it from operating at a level of security that is desired by the administrator.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-24024 — Mjolnir v1.9.0 accepts commands from any room
- CVE-2026-31985 — Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0
- CVE-2026-33389 — Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0
Recently published
- CVE-2026-33389 — Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0
- CVE-2026-31985 — Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0
- CVE-2025-24024 — Mjolnir v1.9.0 accepts commands from any room
More specific weaknesses
- CWE-447 — Unimplemented or Unsupported Feature in UI