Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2022-48290CRITICALThe phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiEPSS 0.4%CVE-2021-31608MEDIUMProofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.EPSS 0.4%CVE-2026-34072HIGHcronmaster: Middleware authentication bypass enabling unauthorized page access and server-action executionEPSS 0.4%CVE-2026-3965MEDIUMwhyour qinglong API express.ts protection mechanismEPSS 0.4%CVE-2026-57133HIGHPraisonAI utility shell safe-command wrapper allowlist bypass via shell chainingEPSS 0.4%CVE-2026-54762MEDIUMTraefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution failsEPSS 0.4%CVE-2026-79774CRITICALWinter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicyEPSS 0.4%CVE-2020-6977—A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs cEPSS 0.4%CVE-2026-45595MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-92938CRITICALvm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqliteEPSS 0.4%CVE-2021-31362MEDIUMJunos OS and Junos OS Evolved: An IS-IS adjacency might be taken down if a bad hello PDU is received for an existing adjacency causing a DoSEPSS 0.4%CVE-2017-6261HIGHNVIDIA’s Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection mechanisms are insufficient, may lead to denial of service or information disclosureEPSS 0.4%CVE-2026-20701HIGHAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS EPSS 0.4%CVE-2025-62453MEDIUMGitHub Copilot and Visual Studio Code Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-48806HIGHTwig: Sandbox `__toString()` policy bypass via dynamic mapping keysEPSS 0.4%CVE-2022-32802HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. ProcessinEPSS 0.4%CVE-2024-11197MEDIUMLock User Account <= 1.0.5 - User Lock BypassEPSS 0.4%CVE-2026-15618MEDIUMmosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection mechanismEPSS 0.4%CVE-2026-8959CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.4%CVE-2026-45655MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.4%