Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2021-3453MEDIUMSome Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker wiEPSS 0.2%CVE-2025-8656MEDIUMKenwood DMX958XR Protection Mechanism Failure Software Downgrade VulnerabilityEPSS 0.2%CVE-2026-14076MEDIUMInsufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security poliEPSS 0.2%CVE-2025-43330HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bEPSS 0.2%CVE-2026-90957MEDIUMMISP: Stored XSS via Inline-Served SVG Organisation Logos and Report PicturesEPSS 0.2%CVE-2026-20277HIGHCisco IOS XR Software Security Hardening Release: September 2026EPSS 0.2%CVE-2020-12954A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPIEPSS 0.2%CVE-2026-44451CRITICALLumiverse: TSX component sandbox escape via DOM ref and string-split identifier bypassEPSS 0.2%CVE-2026-20331CRITICALCisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure VulnerabilitiesEPSS 0.2%CVE-2026-11206MEDIUMInsufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin dataEPSS 0.2%CVE-2026-10174MEDIUMAider-AI Aider Pre-commit Hook args.py protection mechanismEPSS 0.2%CVE-2026-13876MEDIUMInappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypaEPSS 0.2%CVE-2026-45227HIGHHeym < 0.0.21 Sandbox Escape via Python IntrospectionEPSS 0.2%CVE-2026-17931MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictionsEPSS 0.2%CVE-2022-48611HIGHA logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevateEPSS 0.2%CVE-2026-22723MEDIUMUAA User Token Revocation logic errorEPSS 0.2%CVE-2026-9115MEDIUMInsufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origiEPSS 0.2%CVE-2025-31224HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An aEPSS 0.2%CVE-2026-92039MEDIUMMitigation bypass in the DOM: Notifications componentEPSS 0.2%CVE-2026-12027CRITICALInappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the rendererEPSS 0.2%