Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2022-22152HIGHContrail Service Orchestration: Tenants able to see other tenants policies via REST API interfaceEPSS 0.8%CVE-2026-62902MEDIUM.NET Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-32493HIGH Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exEPSS 0.8%CVE-2025-21211MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2023-4039MEDIUMGCC's-fstack-protector fails to guard dynamically-sized local variables on AArch64EPSS 0.8%CVE-2019-3586HIGHMcAfee Endpoint Security firewall not always acting on GTI lookup resultsEPSS 0.8%CVE-2014-125107MEDIUMCorveda PHPSandbox String protection mechanismEPSS 0.8%CVE-2026-24425HIGHTwig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterfaceEPSS 0.8%CVE-2024-1671MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security EPSS 0.8%CVE-2023-39368MEDIUMProtection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable deniEPSS 0.8%CVE-2022-22759CRITICALIf a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document tEPSS 0.7%CVE-2022-22761HIGHWeb-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it wasEPSS 0.7%CVE-2026-92934CRITICALvm2 before 3.11.8 Sandbox Escape RCE via AggregateErrorEPSS 0.7%CVE-2024-28921MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2023-34984HIGHA protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 alloEPSS 0.7%CVE-2024-28903MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2024-30041MEDIUMMicrosoft Bing Search Spoofing VulnerabilityEPSS 0.7%CVE-2023-31273CRITICALProtection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalatioEPSS 0.7%CVE-2024-20665MEDIUMBitLocker Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2024-28920HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%