Weaknesses of type CWE-693

833 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2021-1616MEDIUMCisco IOS XE Software H.323 Application Level Gateway Bypass VulnerabilityEPSS 1.2%CVE-2024-20673HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 1.2%CVE-2026-24781CRITICALvm2: Sandbox Breakout Through InspectEPSS 1.2%CVE-2018-0243A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a confiEPSS 1.2%CVE-2018-0244A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a confiEPSS 1.2%CVE-2018-0254A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configuEPSS 1.2%CVE-2025-24061HIGHWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2026-21669CRITICALA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.EPSS 1.2%CVE-2026-23830CRITICALSandboxJS has Sandbox Escape via Unprotected AsyncFunction ConstructorEPSS 1.2%CVE-2018-0138A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file poEPSS 1.2%CVE-2024-30370MEDIUMRARLAB WinRAR Mark-Of-The-Web Bypass VulnerabilityEPSS 1.2%CVE-2026-53710CRITICALMCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_serverEPSS 1.1%CVE-2026-41316HIGHERB has an @_init deserialization guard bypass via def_module / def_method / def_classEPSS 1.1%CVE-2022-39266CRITICALisolated-vm has vulnerable CachedDataOptions in APIEPSS 1.1%CVE-2022-20738MEDIUMCisco Umbrella Secure Web Gateway File Inspection Bypass VulnerabilityEPSS 1.1%CVE-2021-1494MEDIUMMultiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker tEPSS 1.1%CVE-2023-25765CRITICALIn Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowiEPSS 1.1%CVE-2024-20926MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ScriptiEPSS 1.0%CVE-2025-69264HIGHpnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"EPSS 1.0%CVE-2022-39957HIGHResponse body bypass in OWASP ModSecurity Core Rule Set via a specialy crafted charset in the HTTP Accept headerEPSS 1.0%