CWE-941: Incorrectly Specified Destination in a Communication Channel

low-risk

The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.

Abstraction: Base

Common Consequences

Access Control Gain Privileges or Assume Identity

Real-World Examples (8)

CVE CVSS EPSS KEV
CVE-2024-29415 8.1 84.6%
CVE-2019-18242 7.5 0.5%
CVE-2022-4847 6.5 0.3%
CVE-2024-34947 9.4 0.2%
CVE-2023-33198 6.1 0.2%
CVE-2025-53899 7.2 0.1%
CVE-2025-69515 9.1 0.1%
CVE-2025-0036 3.2 0.0%
4
/ 100
low-risk
Active Threat 4/50 · Minimal
Exploit Availability 0/50 · Minimal