Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2024-20438MEDIUMCisco Nexus Dashboard Fabric Controller Unauthorized REST API VulnerabilityEPSS 0.4%CVE-2026-57137HIGHPraisonAI AgentLoop onToolCall approval runs after tool executionEPSS 0.4%CVE-2026-60086MEDIUMPraisonAI before 4.6.78 Prompt Injection Defense BypassEPSS 0.4%CVE-2024-55024HIGHAn authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorizEPSS 0.4%CVE-2026-67427HIGHFlyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedEPSS 0.4%CVE-2026-53949MEDIUMGhost Content API filter bypass reveals private fieldsEPSS 0.4%CVE-2025-55886MEDIUMAn Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment hisEPSS 0.4%CVE-2026-0881CRITICALSandbox escape in the Messaging System componentEPSS 0.4%CVE-2026-4447HIGHInappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.4%CVE-2026-92038CRITICALMitigation bypass in the Remote Settings Client componentEPSS 0.4%CVE-2026-47424HIGHOpenAM Authenticated RCE via Groovy Sandbox EscapeEPSS 0.4%CVE-2026-92041CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.4%CVE-2025-10528HIGHSandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D componentEPSS 0.4%CVE-2026-17764MEDIUMInappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a cEPSS 0.4%CVE-2025-43728CRITICALDell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remotEPSS 0.4%CVE-2025-14304HIGHASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism FailureEPSS 0.4%CVE-2026-92018CRITICALSandbox escape in the DOM: Core & HTML componentEPSS 0.4%CVE-2026-79684HIGHDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploEPSS 0.3%CVE-2024-24562MEDIUMSecurity headers not set in vantage6-UIEPSS 0.3%CVE-2020-3455MEDIUMCisco FXOS Software for Firepower 4100/9300 Series Appliances Secure Boot Bypass VulnerabilityEPSS 0.3%