CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

64 tracked CVEs are classified under this weakness.

Highest-risk vulnerabilities

Recently published

More specific weaknesses

Browse the full CVE database