BaseDraft
CWE-552Files or Directories Accessible to External Parties
Category: other
Description
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Common consequences· 1
- Confidentiality / Integrity — Read Files or Directories, Modify Files or Directories
Potential mitigations· 1
- [Implementation, System Configuration, Operation]When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to disable public access.
Related CAPEC attack patterns· 2
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Probe System Filescapec-639 | 100% | live |
| AttackPattern | Collect Data from Common Resource Locationscapec-150 | 100% | live |
(incoming)28
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerabilitycve-2025-11371 | 0% | live |
| Vulnerability | CVE-2025-11959cve-2025-11959 | 0% | live |
| Vulnerability | CVE-2025-21609cve-2025-21609 | 0% | live |
| Vulnerability | CVE-2025-26525cve-2025-26525 | 0% | live |
| Vulnerability | CVE-2025-27147cve-2025-27147 | 0% | live |
| Vulnerability | CVE-2025-32819cve-2025-32819 | 0% | live |
| Vulnerability | CVE-2025-37168cve-2025-37168 | 0% | live |
| Vulnerability | CVE-2025-40908cve-2025-40908 | 0% | live |
| Vulnerability | CVE-2025-41240cve-2025-41240 | 0% | live |
| Vulnerability | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerabilitycve-2025-48928 | 0% | live |
| Vulnerability | CVE-2025-53536cve-2025-53536 | 0% | live |
| Vulnerability | CVE-2025-68719cve-2025-68719 | 0% | live |
| Vulnerability | CVE-2025-69990cve-2025-69990 | 0% | live |
| Vulnerability | CVE-2026-2330cve-2026-2330 | 0% | live |
| Vulnerability | CVE-2026-2331cve-2026-2331 | 0% | live |
| Vulnerability | CVE-2026-25137cve-2026-25137 | 0% | live |
| Vulnerability | CVE-2026-31215cve-2026-31215 | 0% | live |
| Vulnerability | CVE-2026-31216cve-2026-31216 | 0% | live |
| Vulnerability | CVE-2026-33071cve-2026-33071 | 0% | live |
| Vulnerability | CVE-2026-33698cve-2026-33698 | 0% | live |
| Vulnerability | CVE-2026-34361cve-2026-34361 | 0% | live |
| Vulnerability | CVE-2026-35446cve-2026-35446 | 0% | live |
| Vulnerability | CVE-2026-40484cve-2026-40484 | 0% | live |
| Vulnerability | CVE-2026-40631cve-2026-40631 | 0% | live |
| Vulnerability | CVE-2026-45721cve-2026-45721 | 0% | live |
| KEVEntry | Roundcube Webmail File Disclosure Vulnerabilitykev-cve-2017-16651 | 0% | live |
| KEVEntry | Apache Flink Improper Access Control Vulnerabilitykev-cve-2020-17519 | 0% | live |
| KEVEntry | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerabilitykev-cve-2025-11371 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.