Weaknesses of type CWE-693

833 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2019-1970MEDIUMCisco Firepower Threat Defense Software File Policy Bypass VulnerabilityEPSS 1.5%CVE-2024-23284MEDIUMA logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iEPSS 1.5%CVE-2020-3285MEDIUMCisco Firepower Threat Defense Software SSL/TLS URL Category Bypass VulnerabilityEPSS 1.5%CVE-2019-12697MEDIUMCisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass VulnerabilitiesEPSS 1.5%CVE-2019-12696MEDIUMCisco Firepower System Software Detection Engine RTF and RAR Malware and File Policy Bypass VulnerabilitiesEPSS 1.5%CVE-2023-29354MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 1.4%CVE-2023-35352HIGHWindows Remote Desktop Security Feature Bypass VulnerabilityEPSS 1.4%CVE-2024-30052MEDIUMVisual Studio Remote Code Execution VulnerabilityEPSS 1.4%CVE-2020-15174HIGHUnpreventable top-level navigation in ElectronEPSS 1.4%CVE-2026-27893HIGHvLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-outEPSS 1.3%CVE-2026-21671CRITICALA vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availabilitEPSS 1.3%CVE-2021-31982HIGHMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 1.3%CVE-2026-22709CRITICALvm2 has a Sandbox EscapeEPSS 1.3%CVE-2019-1669HIGHCisco Firepower Threat Defense Software Packet Inspection and Enforcement Bypass VulnerabilityEPSS 1.2%CVE-2024-5924HIGHDropbox Desktop Folder Sharing Mark-of-the-Web Bypass VulnerabilityEPSS 1.2%CVE-2025-15422MEDIUMEmpireSoft EmpireCMS IP Address connect.php egetip protection mechanismEPSS 1.2%CVE-2024-43487MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2018-0297A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypassEPSS 1.2%CVE-2019-1975MEDIUMCisco HyperFlex Software Cross-Frame Scripting VulnerabilityEPSS 1.2%CVE-2026-32225HIGHWindows Shell Security Feature Bypass VulnerabilityEPSS 1.2%