CWE-1188— Insecure Default Initialization of Resource
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.— MITRE CWE catalog
311 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1188page 4 of 7
- CVE-2023-28978MEDIUMCVSS 5.3EG 5.32023-04-17
An Insecure Default Initialization of Resource vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to read certain confidential information. In the default configuration it is possible to re…
- CVE-2023-31101MEDIUMCVSS 6.5EG 6.52023-05-22
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Use…
- CVE-2023-33949MEDIUMCVSS 5.3EG 5.32023-05-24
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addre…
- CVE-2023-3453HIGHCVSS 7.1EG 7.12023-08-23
ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the configuration of the device or cause a denial-of-service condit…
- CVE-2023-3485LOWCVSS 3.0EG 3.02023-06-30
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done…
- CVE-2023-35689HIGHCVSS 7.8EG 7.82023-08-14
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileg…
- CVE-2023-39169CRITICALCVSS 9.8EG 9.82023-12-07
The affected devices use publicly available default credentials with administrative privileges.
- CVE-2023-40708MEDIUMCVSS 5.8EG 5.82023-08-24
The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an adversary to access some device files.
- CVE-2023-4194MEDIUMCVSS 5.5EG 5.52023-08-07
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomple…
- CVE-2023-45312HIGHCVSS 8.8EG 8.82023-10-10
In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability.
- CVE-2023-48733MEDIUMCVSS 6.7EG 6.72024-02-14
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
- CVE-2023-5368MEDIUMCVSS 6.5EG 6.52023-10-04
On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes. This may permit a us…
- CVE-2023-6448CRITICALCVSS 9.8EG 9.8⚠ KEV2023-12-05
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
- CVE-2024-0001CRITICALCVSS 10.0EG 10.02024-09-23
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
- CVE-2024-0387MEDIUMCVSS 6.5EG 6.52024-02-26
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access con…
- CVE-2024-22207MEDIUMCVSS 5.3EG 5.32024-01-15
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served …
- CVE-2024-22388MEDIUMCVSS 5.9EG 5.92024-02-06
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
- CVE-2024-25610CRITICALCVSS 9.0EG 9.02024-02-20
In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog en…
- CVE-2024-25972HIGHCVSS 8.3EG 8.32024-03-01
Initialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in Japan by Atsumi Electric Co., Ltd. allows a network-adjacent unauthenticated attacker to configure and control the affected product.
- CVE-2024-26267MEDIUMCVSS 5.3EG 5.32024-02-20
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.head…
- CVE-2024-28815CRITICALCVSS 9.8EG 9.82024-03-27
A vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4 through 8.6 could allow access to sensitive information, changes to the system configuration, or execution of arbitrary commands within the cont…
- CVE-2024-2912CRITICALCVSS 10.0EG 10.02024-04-16
An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the …
- CVE-2024-30124MEDIUMCVSS 4.0EG 4.02024-10-23
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
- CVE-2024-31070CRITICALCVSS 9.1EG 9.12024-07-17
Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly.
- CVE-2024-32114HIGHCVSS 8.5EG 8.52024-05-02
In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Pote…
- CVE-2024-34063LOWCVSS 2.5EG 2.52024-05-03
vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secret zeroization capabilities, due to changes in third-party cryptographic dependencies (the Dalek crates), which moved se…
- CVE-2024-34734HIGHCVSS 7.8EG 7.82024-08-15
In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no addition…
- CVE-2024-39916MEDIUMCVSS 6.4EG 6.42024-07-12
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer that allows an attacker to modify files outside the export …
- CVE-2024-41975MEDIUMCVSS 5.3EG 5.32025-03-18
An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.
- CVE-2024-41995HIGHCVSS 7.5EG 7.52024-08-06
Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be affected by some known TLS1.0 and TLS1.1 vulnerabilities. As for th…
- CVE-2024-44096MEDIUMCVSS 4.4EG 4.42024-09-13
there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-45217HIGHCVSS 8.1EG 8.12024-10-16
Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" meta…
- CVE-2024-45313MEDIUMCVSS 5.4EG 5.42024-09-02
Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the configuration for LaTeX compiles was insecure by defa…
- CVE-2024-47295HIGHCVSS 8.1EG 8.12024-10-01
Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary password and operate the device with an administrative privilege. As for the details of the affected versi…
- CVE-2024-48122MEDIUMCVSS 6.7EG 6.72025-01-15
Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileges to escalate to root-level privileges.
- CVE-2024-50390CRITICALCVSS 9.8EG 9.82025-03-07
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.…
- CVE-2024-51758LOWCVSS 2.3EG 2.32024-11-07
Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily swap their storage driv…
- CVE-2024-56433LOWCVSS 3.6EG 3.62024-12-26
shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered net…
- CVE-2024-5801MEDIUMCVSS 5.3EG 5.32024-08-12
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filterin…
- CVE-2024-6788HIGHCVSS 8.6EG 8.62024-08-13
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
- CVE-2024-8313HIGHCVSS 8.7EG 8.72025-03-25
An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based …
- CVE-2024-8383HIGHCVSS 7.5EG 7.52024-09-03
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since mo…
- CVE-2024-9949MEDIUMCVSS 6.1EG 6.12024-10-23
Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application.
- CVE-2025-13357HIGHCVSS 7.4EG 7.42025-11-21
Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthen…
- CVE-2025-14758MEDIUMCVSS 6.5EG 6.52025-12-16
Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows an on-path attacker to read database contents, potentially including credentials
- CVE-2025-1863CRITICALCVSS 9.8EG 9.82025-04-18
Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the affected products. Therefore, when connected to a network with …
- CVE-2025-1960CRITICALCVSS 9.8EG 9.82025-03-12
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized commands when a system’s default password credentials have not been changed on first use. The defau…
- CVE-2025-2129MEDIUMCVSS 5.6EG 5.62025-03-09
A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default initialization of resource. It is possible to initiate the attack remotely. The co…
- CVE-2025-22248HIGHCVSS 7.5EG 7.52025-05-13
The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the us…
- CVE-2025-24288CRITICALCVSS 9.8EG 9.82025-06-19
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa …
Map vulnerabilities like CWE-1188 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1188 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →