Fallos del tipo CWE-477

16 resultados

Uso de funções obsoletas ou descontinuadas

A fraqueza ocorre quando o código utiliza funções, APIs ou bibliotecas que foram marcadas como obsoletas, descontinuadas ou removidas pelos fornecedores. Essas funções frequentemente contêm vulnerabilidades conhecidas, comportamentos não documentados ou deixam de receber correções de segurança, expondo a aplicação a riscos que poderiam ser evitados com alternativas modernas.

Ejemplo

Um sistema legado que ainda usa strcpy() em C para copiar strings, mesmo após décadas de avisos: a função não verifica limites de buffer, causando estouro de pilha. Ou uma aplicação que chama funções OpenSSL descontinuadas no TLS 1.0, perdendo proteção contra ataques conhecidos em protocolos mais novos.

Cómo mitigar

Mantenha dependências e frameworks atualizados, monitore deprecation warnings do compilador/linter, e realize auditorias periódicas do código legado para substituir funções obsoletas por equivalentes modernas. Use ferramentas de análise estática que alertam sobre uso de APIs descontinuadas e estabeleça políticas de versão mínima para bibliotecas críticas.

CVE-2025-49213CRITICALAn insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exeEPSS 9.8%CVE-2025-49212CRITICALAn insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exeEPSS 9.8%CVE-2018-17890NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbEPSS 3.3%CVE-2025-49220CRITICALAn insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execEPSS 2.0%CVE-2019-18251In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of TeamviewEPSS 1.7%CVE-2025-49219CRITICALAn insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code exeEPSS 1.4%CVE-2025-49217CRITICALAn insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exeEPSS 1.1%CVE-2020-6978In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.EPSS 0.8%CVE-2025-49214HIGHAn insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code exEPSS 0.8%CVE-2022-1384MEDIUMAuthorized users are allowed to install old plugin versions from the MarketplaceEPSS 0.6%CVE-2023-23451CRITICALThe Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE4EPSS 0.6%CVE-2025-49216CRITICALAn authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as EPSS 0.5%CVE-2019-10988In Philips HDI 4000 Ultrasound Systems, all versions running on old, unsupported operating systems such as Windows 2000, the HDI 4000 UltrasEPSS 0.3%CVE-2019-10968Philips Holter 2010 Plus, all versions. A vulnerability has been identified that may allow system options that were not purchased to be enabEPSS 0.3%CVE-2026-1693MEDIUMUse of vulnerable Resource Owner Password Credentials flowEPSS 0.3%CVE-2023-28829LOWA vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7EPSS 0.3%