Fallos del tipo CWE-358

114 resultados

Verificação de segurança incompleta ou inadequada para padrão

A aplicação implementa um controle ou validação de segurança, mas de forma insuficiente ou que não cobre todos os casos necessários conforme o padrão esperado. Isso deixa brechas por onde um atacante consegue contornar a proteção ou explorar cenários não previstos na validação.

Ejemplo

Um sistema valida se um arquivo tem extensão .pdf antes de aceitar upload, mas não verifica o conteúdo real do arquivo — atacante envia um executável renomeado para .pdf e consegue executá-lo. Ou um serviço autentica por IP do cliente, mas não valida o token de sessão, deixando a porta aberta para roubo de sessão.

Cómo mitigar

Implemente validações em profundidade (validar não só formato, mas conteúdo, contexto e intenção), siga padrões consolidados de segurança da sua stack (OWASP, RFC de autenticação, etc) e realize testes de contorno — tenha alguém tentando quebrar cada verificação. Code review focado em completude de controles também é crítico.

CVE-2026-11127MEDIUMInappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofEPSS 0.2%CVE-2026-44473HIGHElla Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponseEPSS 0.2%CVE-2025-31969MEDIUMHCL Unica Platform is impacted by misconfigured Content Security Policy (CSP)EPSS 0.2%CVE-2025-66601MEDIUMA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify MIME types. When anEPSS 0.2%CVE-2026-5894MEDIUMInappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via EPSS 0.2%CVE-2025-31970MEDIUMHCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerabilityEPSS 0.1%CVE-2026-44475MEDIUMElla Core: UE Security Capability bypass on NGAP PathSwitchRequestEPSS 0.1%CVE-2025-32086MEDIUMImproperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGXEPSS 0.1%CVE-2026-44474LOWElla Core: Handover failures during concurrent Security Mode CommandEPSS 0.1%CVE-2026-2645MEDIUMAcceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2EPSS 0.1%CVE-2025-31983LOWHCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP headerEPSS 0.1%CVE-2025-58308HIGHVulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerability may cause featuEPSS 0.1%CVE-2025-66323MEDIUMVulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.1%CVE-2024-40650HIGHIn wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalaEPSS 0.1%