Advisor
Wiki Vulnerabilities & Weaknesses Configuration Weaknesses

Configuration Weaknesses 40 articles

01
Default Credentials Usage
Overview Default credentials usage refers to the practice of using factory-set usernames and passwords on devices or software without changing them. This vulnerability arises when these preset credentials remain unchanged…
02
Disabled Security Controls
Overview Disabled security controls refer to protective mechanisms within information systems that have been intentionally or unintentionally turned off or rendered inactive. This vulnerability arises when essential security features such…
03
Excessive Firewall Rules
Overview Excessive firewall rules occur when a firewall configuration contains an overly large number of rules, often including redundant, outdated, or overly permissive entries. This complexity arises from poor management,…
04
Hardcoded Secrets in Configuration Files
Overview Hardcoded secrets in configuration files refer to the practice of embedding sensitive information such as passwords, API keys, or cryptographic keys directly within application or system configuration files. This…
05
Improper Certificate Management
Overview Improper certificate management refers to the inadequate handling, issuance, storage, or renewal of digital certificates used to establish secure communications and verify identities. This weakness arises when organizations fail…
06
Improper Cloud-to-On-Prem Trust Configuration
Overview Improper Cloud-to-On-Prem Trust Configuration refers to weaknesses in the establishment and management of trust relationships between cloud environments and on-premises systems. This vulnerability arises when trust settings are misconfigured,…
07
Improper Logging Configuration
Overview Improper logging configuration refers to the incorrect setup or management of logging mechanisms within software or systems, leading to inadequate, excessive, or insecure recording of events. This weakness arises…
08
Improper Privilege Delegation
Overview Improper Privilege Delegation occurs when an entity is granted more access rights or permissions than necessary to perform its functions, often due to incorrect assignment or transfer of privileges.…
09
Improper Rate Limiting
Overview Improper rate limiting occurs when a system fails to adequately restrict the number of requests or actions a user or client can perform within a given timeframe. This weakness…
10
Improper Secrets Rotation
Overview Improper secrets rotation refers to the failure or inadequate practice of regularly updating cryptographic keys, passwords, tokens, or other sensitive credentials. This weakness arises when secrets remain static for…
11
Improper Time Synchronization
Overview Improper time synchronization refers to the failure of systems to maintain accurate and consistent time across devices and networks. This weakness arises when clocks are not correctly aligned or…
12
Insecure API Gateway Configuration
Overview Insecure API gateway configuration refers to improper setup or management of API gateways that fail to enforce adequate security controls. This vulnerability arises when authentication, authorization, traffic filtering, or…
13
Insecure Authentication Configuration
Overview Insecure authentication configuration refers to weaknesses in the setup or management of authentication mechanisms that fail to adequately verify user identities. This vulnerability arises when authentication controls are improperly…
14
Insecure Backup Configuration
Overview Insecure backup configuration refers to the improper setup or management of backup systems that store copies of critical data. This weakness arises when backups lack adequate protection measures such…
15
Insecure Container Runtime Configuration
Overview Insecure container runtime configuration refers to the improper or unsafe setup of container execution environments, which can lead to vulnerabilities. This weakness arises when default or misconfigured settings expose…
16
Insecure Default Application Settings
Overview Insecure default application settings refer to the configuration choices made by software vendors that prioritize ease of use or functionality over security. These default settings often include enabled services,…
17
Insecure DNS Configuration
Overview Insecure DNS configuration refers to improper setup or management of Domain Name System (DNS) settings that can expose networks and systems to security vulnerabilities. These misconfigurations arise from weak…
18
Insecure File Permission Settings
Overview Insecure file permission settings occur when access controls on files or directories are improperly configured, allowing unauthorized users to read, modify, or execute sensitive data. This vulnerability arises from…
19
Insecure Network Segmentation
Overview Insecure network segmentation occurs when an organization's network is not properly divided into distinct zones or segments, allowing unrestricted communication between systems that should be isolated. This vulnerability arises…
20
Insecure Patch Deployment Configuration
Overview Insecure patch deployment configuration refers to weaknesses in the processes or settings used to apply software patches and updates, which can result in incomplete, delayed, or improperly applied patches.…
1 2 40 articles · page 1 of 2