Weaknesses of type CWE-1220

115 results

Controle de acesso com granularidade insuficiente

A aplicação implementa verificações de permissão muito genéricas, permitindo que um usuário autorizado para uma ação específica execute operações além do escopo pretendido. Por exemplo, um usuário com permissão de 'editar documentos' consegue editar *todos* os documentos, incluindo os de outros usuários ou áreas restritas. O risco é que privilégios amplos demais criam brechas para abuso, mesmo sem quebra autenticação.

Example

Um sistema de gestão de RH verifica se o usuário tem role 'gerente' antes de permitir visualizar salários, mas não valida se aquele gerente está autorizado apenas sobre sua equipe específica. Resultado: qualquer gerente vê salários de toda a empresa.

How to mitigate

Implemente verificações de acesso baseadas em contexto: valide não apenas *quem* está acessando, mas também *o quê* e *em qual escopo* (ex: um editor só modifica seus próprios documentos, um gerente só vê dados de sua filial). Use atributos ou políticas de acesso explícitas por recurso ou usuário.

CVE-2025-35998HIGHMissing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within RinEPSS 0.2%CVE-2025-31961LOWHCL Connections is vulnerable to broken access controlEPSS 0.2%CVE-2025-8306MEDIUMImproper Access Control in Asseco Infomedica PlusEPSS 0.2%CVE-2024-53295HIGHDell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerability. A local maliciousEPSS 0.1%CVE-2025-48514MEDIUMInsufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potEPSS 0.1%CVE-2025-48517MEDIUMInsufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guesEPSS 0.1%CVE-2024-21947HIGHImproper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially reEPSS 0.1%CVE-2024-21971MEDIUMImproper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, rEPSS 0.1%CVE-2026-40145HIGHControl protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utilityEPSS 0.1%CVE-2024-21962HIGHImproper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in pEPSS 0.1%CVE-2021-46747HIGHInsufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to mEPSS 0.1%CVE-2024-33058HIGHInsufficient Granularity of Access Control in CoreEPSS 0.1%CVE-2026-15431HIGHHP Support Assistant – Potential Escalation of PrivilegeEPSS 0.1%CVE-2026-20107MEDIUMCisco Application Policy Infrastructure Controller Denial of Service VulnerabilityEPSS 0.1%CVE-2025-31938MEDIUMInsufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an EPSS 0.1%