CWE · MITRE source
CWE-941Incorrectly Specified Destination in a Communication Channel
The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.
Attackers at the destination may be able to spoof trusted servers to steal data or cause a denial of service. There are at least two distinct weaknesses that can cause the product to communicate with an unintended destination:
Last updated: 20 August 2026 13:14 UTC
OWASP Top 10 for Web (2025)
This weakness contributes to A07:2025 Authentication Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2024-34947 UPD | 7.0 | 9.4 | 0.0039 | 2024-05-20 |
CVE-2024-29415 UPD | 6.9 | 8.1 | 0.0828 | 2024-05-27 |
CVE-2025-69515 UPD | 6.9 | 9.1 | 0.0046 | 2026-04-07 |
CVE-2019-18242 UPD | 6.2 | 7.5 | 0.0161 | 2020-03-24 |
CVE-2025-53899 | 5.6 | 7.2 | 0.0092 | 2025-11-29 |
CVE-2022-4847 UPD | 5.2 | 6.5 | 0.0064 | 2022-12-29 |
CVE-2026-69246 | 5.2 | 7.2 | 0.0021 | 2026-08-03 |
CVE-2026-40118 | 4.8 | 6.3 | 0.0018 | 2026-04-16 |
CVE-2023-33198 UPD | 4.7 | 6.1 | 0.0063 | 2023-05-30 |
CVE-2026-72506 | 4.2 | 5.4 | 0.0018 | 2026-08-13 |
CVE-2025-0036 UPD | 2.6 | 3.2 | 0.0013 | 2025-06-10 |