Weaknesses of type CWE-693

833 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2018-0094A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a EPSS 2.3%CVE-2020-3315MEDIUMMultiple Cisco Products Snort HTTP Detection Engine File Policy Bypass VulnerabilityEPSS 2.2%CVE-2023-33150CRITICALMicrosoft Office Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2024-26163MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2021-1224MEDIUMMultiple Cisco Products Snort TCP Fast Open File Policy Bypass VulnerabilityEPSS 2.0%CVE-2021-1223MEDIUMMultiple Cisco Products Snort HTTP Detection Engine File Policy Bypass VulnerabilityEPSS 2.0%CVE-2025-21217MEDIUMWindows NTLM Spoofing VulnerabilityEPSS 1.9%CVE-2022-21626MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions tEPSS 1.9%CVE-2018-0333A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to byEPSS 1.9%CVE-2018-0326A vulnerability in the web UI of Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to conduct a cross-frameEPSS 1.8%CVE-2025-33050HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 1.8%CVE-2025-32725HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 1.8%CVE-2018-0198A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitiEPSS 1.7%CVE-2019-1833MEDIUMCisco Firepower Threat Defense Software SSL/TLS Policy Bypass VulnerabilityEPSS 1.7%CVE-2019-1832MEDIUMCisco Firepower Threat Defense Software Detection Engine Policy Bypass VulnerabilityEPSS 1.6%CVE-2025-27472MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 1.6%CVE-2024-38092HIGHAzure CycleCloud Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2024-38180HIGHWindows SmartScreen Security Feature Bypass VulnerabilityEPSS 1.6%CVE-2022-36085HIGHOPA Compiler: Bypass of WithUnsafeBuiltins using `with` keyword to mock functionsEPSS 1.6%CVE-2023-32006HIGHThe use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition foEPSS 1.5%