šŸš€ Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

Insecure Default Configuration

The product initializes or sets a resource with a default configuration that is intended to be changed by an installer, administrator, or maintainer, but the default is not secure. If these insecure defaults remain unchanged, attackers may exploit exposed functionality, bypass security controls, or gain unauthorized access depending on the affected resource.

Remediation

To remediate this vulnerability, systems should be deployed with secure defaults that minimize exposure and restrict unnecessary functionality. Configuration values such as permissions, authentication settings, and network access controls should be explicitly initialized to safe states, and administrators should be required to review and modify security-sensitive defaults during installation or deployment.

Metadata

  • Severity: medium
  • Slug: insecure-default-configuration

CWEs

  • 1188: Insecure Default Initialization of Resource

Available Labs

Select a language to explore available labs for this vulnerability.

No matching labs found

Try adjusting your language filter.

Try it yourself

Find, Hack and Fix Your First Vulnerability

Reading about security bugs is one thing — fixing one is how the skill sticks. Play a free challenge from the wargame, no setup required.