Fallos del tipo CWE-636

57 resultados

Fallback para estado menos seguro em caso de erro

A aplicação, ao encontrar um erro ou falha, recai automaticamente para um modo operacional menos seguro em vez de outras opções disponíveis. Isso pode significar usar algoritmo criptográfico mais fraco, relaxar controles de acesso ou desabilitar verificações de segurança. O risco é que o atacante provoque intencionalmente a falha para forçar a aplicação a operar em modo inseguro.

Ejemplo

Um cliente TLS tenta negociar cifras fortes com o servidor; se falhar, cai para HTTP simples ou SSL 3.0 quebrado. Ou um sistema de autenticação que, ao falhar validação via PKI, aceita login com senha fraca ou até sem autenticação.

Cómo mitigar

Não implemente fallbacks automáticos para modos menos seguros. Se há degradação de segurança, interrompa a operação, registre o evento e alerte o administrador. Garanta que o 'modo seguro' seja a única opção viável, sem alternativas fracas.

CVE-2026-54291HIGHSilent channel-binding authentication downgrade via unsupported certificate algorithmsEPSS 0.2%CVE-2026-41377MEDIUMOpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin InstallationEPSS 0.2%CVE-2026-35205HIGHHelm's plugin verification fails open when .prov is missing, allowing unsigned plugin installEPSS 0.2%CVE-2026-86120MEDIUMAPITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node Permission GuardEPSS 0.2%CVE-2026-85649HIGH(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root uEPSS 0.2%CVE-2026-45781LOWMCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claimsEPSS 0.2%CVE-2026-53852LOWOpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairingEPSS 0.2%CVE-2025-54870HIGHVTun-ng's failure to initialize encryption modules may cause reversion to plaintextEPSS 0.2%CVE-2026-53837MEDIUMOpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event HandlersEPSS 0.2%CVE-2023-4030HIGHA vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover toEPSS 0.2%CVE-2026-82018MEDIUMIGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf FileEPSS 0.2%CVE-2026-35042HIGHfast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)EPSS 0.2%CVE-2026-55568MEDIUMGuzzle: Silent HTTPS-Proxy Downgrade to CleartextEPSS 0.1%CVE-2026-49317LOWIndian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at bootEPSS 0.1%CVE-2026-49318LOWIndian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at bootEPSS 0.1%CVE-2026-82744LOWAsh.Reactor change step fails open, skipping a change when its where guard raisesEPSS 0.1%CVE-2026-32970LOWOpenClaw < 2026.3.11 - Credential Fallback Logic Bypass via Unavailable Local Auth SecretRefsEPSS 0.1%