CWE-15

External Control of System or Configuration Setting

Parent: CWE-642 - External Control of Critical State Data

One or more system settings or configuration elements can be externally controlled by a user.

65 vulnerabilities with CWE-15
CVE-2025-27889 LOW
Wing FTP Server <7.4.4 - Code Injection
CVSS 3.4
CVE-2025-30512 MEDIUM
Growatt Cloud Portal <= 3.6.0 - Unauthenticated Remote Configuration Manipulation
CVSS 6.5
CVE-2025-27253 MEDIUM
GE Vernova UR IED <8.60 - Info Disclosure
CVSS 6.1
CVE-2025-0425 HIGH
bestinformed Infoclient - Privilege Escalation
CVE-2024-11166 HIGH
Traffic Alert and Collision Avoidance System (TCAS) II - Denial of Service via Comm-A Identity Request
CVE-2024-39800 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39799 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39798 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39795 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Permission Bypass
CVSS 9.1
CVE-2024-39794 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39793 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39790 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39789 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Config Injection
CVSS 9.1
CVE-2024-39788 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Config Injection
CVSS 9.1
CVE-2024-39602 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39280 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-38666 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Command Injection
CVSS 9.1
CVE-2024-54097 HIGH
Huawei EMUI and HarmonyOS - External Control of System Setting in HiView Module
CVSS 7.3
CVE-2024-51544 HIGH
ABB ASPECT Enterprise NEXUS and MATRIX Series < 3.08.03 - Unauthenticated Service Control and Configuration Modification
CVSS 8.2
CVE-2024-51543 HIGH
ABB ASPECT <3.08.02, NEXUS Series <3.08.02, MATRIX Series <3.08.02 ...
CVSS 8.2
CVE-2024-50358 HIGH
Advantech - External Control of System or Configuration Setting
CVSS 7.2
CVE-2024-10979 HIGH
PostgreSQL <17.1-12.21 - Code Injection
CVSS 8.8
CVE-2024-21583 MEDIUM
github.com/gitpod-io/gitpod - Info Disclosure
CVSS 4.1
CVE-2024-4326 CRITICAL
lollms_web_ui < 9.5 - Remote Code Execution via Settings Bypass
CVSS 9.8
CVE-2024-23639 MEDIUM
Micronaut Framework - Info Disclosure
CVSS 5.1
Details
Vulnerabilities 65