Weaknesses of type CWE-693

835 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2025-46290HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS SequoEPSS 0.9%CVE-2026-20824MEDIUMWindows Remote Assistance Security Feature Bypass VulnerabilityEPSS 0.9%CVE-2023-5557HIGHTracker-miners: sandbox escapeEPSS 0.9%CVE-2024-45411HIGHTwig has a possible sandbox bypassEPSS 0.8%CVE-2021-27497MEDIUMPhilips Vue PACS Protection Mechanism FailureEPSS 0.8%CVE-2025-26637MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2021-36310MEDIUMDell Networking OS10, versions 10.4.3.x, 10.5.0.x, 10.5.1.x & 10.5.2.x, contain an uncontrolled resource consumption flaw in its API serviceEPSS 0.8%CVE-2026-33396CRITICALOneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on ProbeEPSS 0.8%CVE-2023-23589MEDIUMThe SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protoEPSS 0.8%CVE-2025-47160MEDIUMWindows Shortcut Files Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2019-13924A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versionsEPSS 0.8%CVE-2021-1517MEDIUMCisco Webex Meetings and Webex Meetings Server Multimedia Sharing Security Bypass VulnerabilityEPSS 0.8%CVE-2023-28284MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2026-47140CRITICALvm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code executionEPSS 0.8%CVE-2022-33631HIGHMicrosoft Excel Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2025-43261CRITICALA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An aEPSS 0.8%CVE-2023-45132CRITICALIgnoreIP/IgnoreCIDR should not trust X-Forwarded-ForEPSS 0.8%CVE-2025-10157CRITICALPickleScan Bypasses Unsafe Globals Check Using Submodule ImportsEPSS 0.8%CVE-2018-1170This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen EPSS 0.8%CVE-2025-49740HIGHWindows SmartScreen Security Feature Bypass VulnerabilityEPSS 0.8%