Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2024-0747MEDIUMWhen a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child ContEPSS 0.6%CVE-2025-3114CRITICALSpotfire Code Execution VulnerabilityEPSS 0.6%CVE-2023-0131MEDIUMInappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download EPSS 0.6%CVE-2026-92124HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from aEPSS 0.6%CVE-2026-92123HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, pEPSS 0.6%CVE-2025-48800MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2022-41979MEDIUMProtection mechanism failure in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalatioEPSS 0.6%CVE-2024-21423MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-28286MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-92944CRITICALvm2 3.10.2 through 3.11.6 Sandbox Escape via Promise ProtectorEPSS 0.6%CVE-2025-43413HIGHAn access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, mEPSS 0.6%CVE-2022-43432MEDIUMJenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user-generated content iEPSS 0.6%CVE-2026-76825HIGHRestrictedPython: Sandbox escape via string.Formatter field resolutionEPSS 0.6%CVE-2025-48003MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2020-28396—A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V16), SICAM A8000 CP-8021 (All versions < V16), SICAM A8000 CP-80EPSS 0.6%CVE-2025-50329CRITICALAn issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code vEPSS 0.6%CVE-2025-65319CRITICALWhen using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-WeEPSS 0.6%CVE-2026-14535HIGHFickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()EPSS 0.6%CVE-2020-16198MEDIUMPhilips Clinical Collaboration Platform Protection Mechanism FailureEPSS 0.6%CVE-2026-34208CRITICALSandboxJS: Sandbox integrity escapeEPSS 0.6%