Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2024-38660LOWProtection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated user to potentially eEPSS 0.2%CVE-2025-12906MEDIUMInappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2025-66479LOWAnthropic Sandbox Runtime Incorrectly Implemented Network SandboxingEPSS 0.2%CVE-2026-8011MEDIUMInsufficient policy enforcement in Search in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a EPSS 0.2%CVE-2026-8014MEDIUMInappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crEPSS 0.2%CVE-2025-67460HIGHZoom Rooms for Windows - Software Downgrade Protection Mechanism FailureEPSS 0.2%CVE-2025-52609LOWHCL iControl was affected by Missing Security Headers vulnerability.EPSS 0.2%CVE-2026-15528MEDIUMlamaalrajih kicad-mcp path_validator.py protection mechanismEPSS 0.2%CVE-2026-49325MEDIUMIndian Scout Bobber 2025 WCM voltage-based shutdownEPSS 0.2%CVE-2026-8572LOWInsufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromisedEPSS 0.2%CVE-2026-28899MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS TEPSS 0.2%CVE-2023-42918HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to cEPSS 0.2%CVE-2026-5900MEDIUMPolicy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a cEPSS 0.2%CVE-2026-73083HIGHActivepieces: V8 Isolate Sandbox Bypass via importFresh Module LoadingEPSS 0.2%CVE-2026-84570MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app EPSS 0.2%CVE-2026-0278MEDIUMPrisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on WindowsEPSS 0.2%CVE-2026-5896MEDIUMPolicy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestuEPSS 0.2%CVE-2026-21387MEDIUMProtection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilegeEPSS 0.2%CVE-2026-20903MEDIUMProtection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation EPSS 0.2%CVE-2026-21400MEDIUMProtection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring 3: User Applications may allow an escalEPSS 0.2%