Weaknesses of type CWE-494

188 results

Escalação de Privilégio

É quando um atacante consegue elevar suas permissões no sistema além do que deveria ter acesso — por exemplo, passando de usuário comum para administrador. Acontece porque o software não valida adequadamente quem pode executar certas operações sensíveis, ou confia em dados que podem ser manipulados.

Example

Um aplicativo web que guarda o nível de acesso do usuário em um cookie do lado do cliente (tipo 'role=user') permite que o atacante edite o cookie para 'role=admin' e ganhe acesso a funcionalidades administrativas. Outro caso: um programa Linux que roda com setuid mas não valida argumentos antes de executar comandos do sistema.

How to mitigate

Sempre valide e controle privilégios no servidor/backend, nunca confie em dados do cliente. Use listas de controle de acesso (ACL) ou modelos RBAC bem implementados, e garanta que operações sensíveis exigem reauthenticação ou tokens seguros que não podem ser falsificados.

CVE-2023-46143HIGHPhoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLCEPSS 0.3%CVE-2023-5592HIGHPhoenix Contact: ProConOs prone to Download of Code Without Integrity CheckEPSS 0.3%CVE-2026-66398CRITICALphpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIEPSS 0.3%CVE-2026-63696CRITICALDell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privilEPSS 0.3%CVE-2023-37220HIGHSynel Terminals - CWE-494: Download of Code Without Integrity CheckEPSS 0.3%CVE-2026-28500HIGHONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain AttackEPSS 0.3%CVE-2022-4261MEDIUMRapid7 Nexpose Update Validation IssueEPSS 0.3%CVE-2026-9089HIGHThe ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatioEPSS 0.3%CVE-2023-46144MEDIUMPHOENIX CONTACT: PLCnext Control prone to download of code without integrity checkEPSS 0.3%CVE-2025-63434HIGHThe update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts upEPSS 0.3%CVE-2026-30612CRITICALAn issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a EPSS 0.3%CVE-2024-30206HIGHA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.3%CVE-2023-5984HIGH A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be uploaded when an authorizeEPSS 0.3%CVE-2025-31355HIGHA firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially craftEPSS 0.3%CVE-2026-55698HIGHpnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesEPSS 0.3%CVE-2026-33075CRITICALFastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.ymlEPSS 0.3%CVE-2026-65081HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. AEPSS 0.3%CVE-2023-47353HIGHAn issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitraEPSS 0.3%CVE-2025-30199HIGHECOVACS Vacuum and Base Station accept unsigned firmwareEPSS 0.3%CVE-2022-38199MEDIUMBUG-000144172 - Remote file download issue in ArcGIS ServerEPSS 0.3%