Fallos del tipo CWE-602

174 resultados

Confiança em mecanismo de segurança implementado no cliente

O servidor delega a responsabilidade de uma proteção de segurança para o cliente executar, assumindo que ele vai cumprir. Isso é perigoso porque um atacante controla o cliente e pode simplesmente ignorar, contornar ou desabilitar essa proteção, deixando o servidor vulnerável.

Ejemplo

Um servidor web que valida permissões de acesso apenas via JavaScript no navegador, sem verificar novamente no backend. Um atacante desabilita o JavaScript ou intercepta a requisição, acessando dados que não deveria.

Cómo mitigar

Implemente toda validação crítica de segurança no servidor, nunca confie em verificações feitas apenas no cliente. O cliente pode fazer validação por UX, mas o servidor deve sempre validar independentemente autenticação, autorização, entrada de dados e regras de negócio.

CVE-2022-1525CRITICALCognex 3D-A1000 Dimensioning System Client-Side Enforcement of Server-Side SecurityEPSS 0.8%CVE-2020-5345MEDIUMDell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, anEPSS 0.7%CVE-2025-27681CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-EPSS 0.7%CVE-2022-3308HIGHInsufficient policy enforcement in developer tools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially perform EPSS 0.7%CVE-2023-0581MEDIUMPrivateContent <= 8.4.3 - Protection Mechanism BypassEPSS 0.7%CVE-2026-54104HIGHU.S. GAO EPDS and CBCA EDS client-based privilege escalationEPSS 0.7%CVE-2021-21531HIGHDell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user wiEPSS 0.7%CVE-2025-40591HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEEPSS 0.7%CVE-2026-45274MEDIUMMyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER EnforcementEPSS 0.7%CVE-2023-23570MEDIUM Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undeEPSS 0.7%CVE-2024-28029HIGHClient-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergieEPSS 0.7%CVE-2026-42266HIGHJupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.EPSS 0.6%CVE-2025-4527MEDIUMDígitro NGC Explorer Password Transmission client-side enforcement of server-side securityEPSS 0.6%CVE-2024-0701MEDIUMUserPro <= 5.1.6 - Disabled Membership Registration BypassEPSS 0.6%CVE-2022-3047MEDIUMInsufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to instalEPSS 0.6%CVE-2024-52008LOWPassword Policy Bypass Vulnerability in Fides WebserverEPSS 0.6%CVE-2024-12603CRITICALA logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.EPSS 0.6%CVE-2022-3310MEDIUMInsufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the userEPSS 0.5%CVE-2026-30933HIGHFileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/infoEPSS 0.5%CVE-2020-27268—In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDanEPSS 0.5%