Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2024-20438MEDIUMCisco Nexus Dashboard Fabric Controller Unauthorized REST API VulnerabilityEPSS 0.4%CVE-2026-57137HIGHPraisonAI AgentLoop onToolCall approval runs after tool executionEPSS 0.4%CVE-2026-60086MEDIUMPraisonAI before 4.6.78 Prompt Injection Defense BypassEPSS 0.4%CVE-2024-55024HIGHAn authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorizEPSS 0.4%CVE-2026-67427HIGHFlyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedEPSS 0.4%CVE-2026-53949MEDIUMGhost Content API filter bypass reveals private fieldsEPSS 0.4%CVE-2025-55886MEDIUMAn Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment hisEPSS 0.4%CVE-2026-0881CRITICALSandbox escape in the Messaging System componentEPSS 0.4%CVE-2026-4447HIGHInappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.4%CVE-2026-92038CRITICALMitigation bypass in the Remote Settings Client componentEPSS 0.4%CVE-2026-47424HIGHOpenAM Authenticated RCE via Groovy Sandbox EscapeEPSS 0.4%CVE-2026-92041CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.4%CVE-2025-10528HIGHSandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D componentEPSS 0.4%CVE-2026-17764MEDIUMInappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a cEPSS 0.4%CVE-2025-43728CRITICALDell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remotEPSS 0.4%CVE-2025-14304HIGHASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism FailureEPSS 0.4%CVE-2026-92018CRITICALSandbox escape in the DOM: Core & HTML componentEPSS 0.4%CVE-2026-79684HIGHDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploEPSS 0.3%CVE-2024-24562MEDIUMSecurity headers not set in vantage6-UIEPSS 0.3%CVE-2020-3455MEDIUMCisco FXOS Software for Firepower 4100/9300 Series Appliances Secure Boot Bypass VulnerabilityEPSS 0.3%