Weaknesses of type CWE-691

36 results

Controle de fluxo insuficiente

Ocorre quando o software não gerencia adequadamente o fluxo de execução, permitindo que código não planejado seja executado ou que verificações de segurança sejam contornadas. A falta de controle explícito sobre qual código roda e em que ordem cria brechas para escalação de privilégio ou execução de operações não autorizadas.

Example

Uma aplicação valida permissões ao início de uma função, mas não reinicia a validação dentro de callbacks ou threads assíncronos. Um usuário sem privilégio consegue explorar a execução descontrolada para acessar recursos administrativos.

How to mitigate

Implemente verificações de autorização em pontos-chave do fluxo (especialmente antes de operações sensíveis), use máquinas de estado para controlar transições legítimas e evite desvios implícitos. Testes de penetração focados em fluxo alternativo ajudam a identificar caminhos não previstos.

CVE-2024-29079MEDIUMInsufficient control flow management in some Intel(R) VROC software before version 8.6.0.3001 may allow an authenticated user to potentiallyEPSS 0.2%CVE-2021-33157HIGHInsufficient control flow management in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allEPSS 0.2%CVE-2025-35963HIGHInsufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: DeviceEPSS 0.2%CVE-2024-21801HIGHInsufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentEPSS 0.2%CVE-2023-24587MEDIUMInsufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enableEPSS 0.2%CVE-2024-25565MEDIUMInsufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial EPSS 0.2%CVE-2023-28711MEDIUMInsufficient control flow management in the Hyperscan Library maintained by Intel(R) before version 5.4.1 may allow an authenticated user toEPSS 0.2%CVE-2022-37409MEDIUMInsufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potEPSS 0.2%CVE-2022-41646MEDIUMInsufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to poEPSS 0.2%CVE-2022-43505MEDIUMInsufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denEPSS 0.2%CVE-2024-22374MEDIUMInsufficient control flow management for some Intel(R) Xeon Processors may allow an authenticated user to potentially enable denial of serviEPSS 0.2%CVE-2025-20004HIGHInsufficient control flow management in the Alias Checking Trusted Module for some Intel(R) Xeon(R) 6 processor E-Cores firmware may allow aEPSS 0.1%CVE-2025-24305HIGHInsufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) processors may allow a pEPSS 0.1%CVE-2025-25273HIGHInsufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow aEPSS 0.1%CVE-2025-22893HIGHInsufficient control flow management in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow aEPSS 0.1%CVE-2026-5938MEDIUMFoxit PDF Editor/Reader Infinite Loop Denial-of-Service VulnerabilityEPSS 0.1%