Weaknesses of type CWE-693

819 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2025-48602HIGHIn exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic erroEPSS 0.1%CVE-2026-0293MEDIUMPrisma Access Agent: Anti-Tamper Protection Bypass on WindowsEPSS 0.1%CVE-2026-86909MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass GatekeEPSS 0.1%CVE-2025-27700HIGHThere is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no adEPSS 0.1%CVE-2026-40604HIGHClearanceKit: opfilter system extension can be suspended or signalled by a root process, disabling file-access policy enforcementEPSS 0.1%CVE-2026-0306MEDIUMPrisma Access Agent: EndPoint DLP Bypass Vulnerability on WindowsEPSS 0.1%CVE-2025-0089HIGHIn multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalatEPSS 0.1%CVE-2026-0012MEDIUMIn setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This coulEPSS 0.1%CVE-2026-57012HIGHIn the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of pEPSS 0.1%CVE-2025-48635HIGHIn multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. ThiEPSS 0.1%CVE-2026-58767MEDIUMIn multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to locEPSS 0.1%CVE-2023-21024HIGHIn maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error. This could lead to local escalation ofEPSS 0.1%CVE-2022-20464MEDIUMIn various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. EPSS 0.1%CVE-2025-48653HIGHIn loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could EPSS 0.1%CVE-2025-48531HIGHIn getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to loEPSS 0.1%CVE-2025-32331HIGHIn showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This couEPSS 0.1%CVE-2026-0017HIGHIn onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could leadEPSS 0.1%CVE-2025-48522HIGHIn setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code.EPSS 0.1%CVE-2025-26464HIGHIn executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. ThisEPSS 0.1%CVE-2025-52643MEDIUMHCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environmentEPSS 0.1%