Medium severity Vulnerability

Security Misconfiguration

Default credentials, verbose errors, open cloud buckets and unnecessary services widen the attack surface.

Overview

This covers everything that is insecure because nobody changed the default: sample apps left in production, directory listing enabled, stack traces shown to visitors, debug ports exposed, permissive CORS, and cloud storage set to public read.\nIt is the easiest class to exploit and the cheapest to fix through hardened baselines and repeated configuration review.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Default admin/admin logins
  • Full stack traces in HTTP 500 pages
  • Public S3 or blob containers

Controls that stop it

  • Patch Promptly and Continuously

    Maintain an inventory of every framework, plugin and library you run, subscribe to their advisories, and apply fixes on a defined SLA measured in days rather than months. Prioritise anything reachable from the internet or already exploited in the wild. Automate the process so patching does not depend on someone remembering to do it.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used