目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-602 服务端安全的客户端实施 类漏洞列表 109

CWE-602 服务端安全的客户端实施 类弱点 109 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-602 指客户端执行服务端安全机制的漏洞,属于逻辑设计缺陷。攻击者通过修改客户端代码或拦截请求,绕过前端限制直接与服务端交互,从而获取未授权访问或执行恶意操作。开发者应避免依赖前端进行敏感验证,必须确保所有安全控制逻辑均在服务端独立实施,以保障数据完整性与系统安全性。

MITRE CWE 官方描述
CWE:CWE-602 客户端执行服务端安全(Client-Side Enforcement of Server-Side Security) 英文:该产品由一个服务器组成,该服务器依赖客户端来实现旨在保护服务器的机制。 当服务器依赖放置在客户端的保护机制时,攻击者可以修改客户端行为以绕过这些保护机制,从而导致客户端与服务器之间出现潜在的意外交互。后果将因这些机制试图保护的内容不同而有所差异。
常见影响 (2)
Access Control, Availability Bypass Protection Mechanism, DoS: Crash, Exit, or Restart
Client-side validation checks can be easily bypassed, allowing malformed or unexpected input to pass into the application, potentially as trusted data. This may lead to unexpected states, behaviors and possibly a resulting crash.
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity
Client-side checks for authentication can be easily bypassed, allowing clients to escalate their access levels and perform unintended actions.
缓解措施 (2)
Architecture and Design For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server. Even though client-side checks provide minim…
Architecture and Design If some degree of trust is required between the two entities, then use integrity checking and strong authentication to ensure that the inputs are coming from a trusted source. Design the product so that this trust is managed in a centralized fashion, especially if there are complex or numerous communication channels, in order to reduce the risks that the implementer will mistakenly omit a check in…
代码示例 (2)
This example contains client-side code that checks if the user authenticated successfully before sending a command. The server-side code performs the authentication in one step, and executes the command in a separate step.
$server = "server.example.com"; $username = AskForUserName(); $password = AskForPassword(); $address = AskForAddress(); $sock = OpenSocket($server, 1234); writeSocket($sock, "AUTH $username $password\n"); $resp = readSocket($sock); if ($resp eq "success") { # username/pass is valid, go ahead and update the info! writeSocket($sock, "CHANGE-ADDRESS $username $address\n"; } else { print "ERROR: Invalid Authentication!\n"; }
Good · Perl
$sock = acceptSocket(1234); ($cmd, $args) = ParseClientRequest($sock); if ($cmd eq "AUTH") { ($username, $pass) = split(/\s+/, $args, 2); $result = AuthenticateUser($username, $pass); writeSocket($sock, "$result\n"); # does not close the socket on failure; assumes the # user will try again } elsif ($cmd eq "CHANGE-ADDRESS") { if (validateAddress($args)) { $res = UpdateDatabaseRecord($username, "address", $args); writeSocket($sock, "SUCCESS\n"); } else { writeSocket($sock, "FAILURE -- address is malformed\n"); } }
Bad · Perl
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID 标题 CVSS 风险等级 Published
CVE-2023-20172 Cisco Identity Services Engine 输入验证错误漏洞 — Cisco Identity Services Engine Software 5.4 Medium 2023-05-18
CVE-2023-20171 Cisco Identity Services Engine 输入验证错误漏洞 — Cisco Identity Services Engine Software 5.4 Medium 2023-05-18
CVE-2023-20106 Cisco Identity Services Engine 安全漏洞 — Cisco Identity Services Engine Software 5.4 Medium 2023-05-18
CVE-2023-0750 LYNX Technik Yellobrik PEC-1864 安全漏洞 — Yellowbrik 9.8 Critical 2023-04-06
CVE-2023-0581 WordPress plugin PrivateContent 安全漏洞 — PrivateContent 5.3 Medium 2023-01-30
CVE-2022-1525 Cognex 3D-A1000 Dimensioning System 安全漏洞 — 3D-A1000 Dimensioning System 9.1 Critical 2022-09-06
CVE-2022-31233 Dell EMC Unisphere for PowerMax 安全漏洞 — Unisphere for PowerMax 6.3 Medium 2022-08-31
CVE-2021-36338 Dell EMC Unisphere for PowerMax 安全漏洞 — Unisphere for PowerMax 6.3 Medium 2022-01-21
CVE-2022-20658 Cisco Unified Contact Center Management Portal和Cisco Unified Contact Center Domain Manager 安全漏洞 — Cisco Unified Contact Center Domain Manager 9.6 Critical 2022-01-14
CVE-2021-21531 Dell EMC Unisphere for PowerMax 安全漏洞 — Unisphere for PowerMax 8.1 High 2021-04-30
CVE-2021-21544 Dell EMC iDRAC9 授权问题漏洞 — Integrated Dell Remote Access Controller (iDRAC) 2.7 Low 2021-04-30
CVE-2020-27268 多款Sooil产品授权问题漏洞 — SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A 6.5 - 2021-01-19
CVE-2020-24683 ABB Symphony Plus Operations 访问控制错误漏洞 — ABB Ability™ Symphony® Plus Operations 9.8 Critical 2020-12-22
CVE-2020-5345 多款Dell产品安全漏洞 — Unisphere for PowerMax 6.4 Medium 2020-06-23
CVE-2020-8162 Ruby on Rails 代码问题漏洞 — https://github.com/rails/rails 7.5 - 2020-06-19
CVE-2017-12161 Red Hat keycloak 安全漏洞 — Keycloak 8.8 - 2018-02-21
CVE-2017-14013 ProMinent MultiFLEX M10a Controller Web界面安全漏洞 — ProMinent MultiFLEX M10a Controller 7.7 - 2017-10-17
CVE-2014-2373 Accuenergy Acuvim II AXN-NET Ethernet模块配件授权问题漏洞 — Accuenergy Acuvim II AXN-NET Ethernet module 9.1 - 2014-11-05
CVE-2014-2374 Accuenergy Acuvim II AXN-NET Ethernet模块配件信息泄露漏洞 — Accuenergy Acuvim II AXN-NET Ethernet module 9.1 - 2014-11-05

CWE-602(服务端安全的客户端实施) 是常见的弱点类别,本平台收录该类弱点关联的 109 条 CVE 漏洞。