Security Misconfiguration
Insecure settings in an application, framework, server, cloud service or device, such as default credentials, unnecessary features, verbose error messages or publicly exposed storage, that leave systems open to attack.
Security misconfiguration covers weaknesses that arise from how software is set up rather than from coding flaws. Examples include default accounts and passwords left enabled; unnecessary ports, services, sample applications or debug modes; directory listing; detailed stack traces returned to users; missing security headers; outdated TLS settings; and cloud storage buckets or databases exposed to the internet without authentication. In the OWASP Top 10 2021 it ranked fifth and absorbed the former XML External Entities (XXE) category.
The problem is widespread because modern technology stacks involve many layers, each with its own defaults, and because cloud and container platforms make it easy to deploy resources quickly. Misconfigured cloud storage and exposed management interfaces are frequent causes of data exposure, and devices shipped with default credentials, including industrial equipment, are a recurring finding in security assessments.
Prevention relies on a repeatable hardening process: minimal installations, documented secure baselines such as the CIS Benchmarks, configuration managed as code, consistent settings across development, test and production with different credentials in each, and automated checks that detect drift. Cloud security posture management tools and periodic external scans help find exposures before attackers do.
Key points
- Arises from insecure settings rather than from coding errors.
- Ranked fifth in the OWASP Top 10 2021, which merged XXE into this category.
- Secure baselines such as the CIS Benchmarks guide system hardening.
- Configuration as code and drift detection keep settings consistent.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- OWASP Top 10Cybersecurity & Compliance
- HTTP Security HeadersCybersecurity & Compliance
- Transport Layer Security (TLS)Cybersecurity & Compliance
- Vulnerability ManagementCybersecurity & Compliance
- KubernetesCloud & AI Infrastructure
- Secrets ManagementCybersecurity & Compliance