Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2021-35556MEDIUMVulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are afEPSS 8.5%CVE-2017-10952—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interactioEPSS 7.2%CVE-2017-3197—GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protectionEPSS 5.6%CVE-2022-32845CRITICALThis issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app mayEPSS 5.4%CVE-2021-32835—Groovy Sandbox escape in Eclipse KetiEPSS 4.6%CVE-2020-10887HIGHThis vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. AuthenticatiEPSS 4.2%CVE-2022-42821MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An aEPSS 3.9%CVE-2022-21283MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions EPSS 3.8%CVE-2021-27245HIGHThis vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 prior to Archer C7(US)_V5_210125 and Archer A7(USEPSS 3.2%CVE-2018-0383—A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a file EPSS 3.0%CVE-2022-35978HIGHLua sandbox escape from mod in MinetestEPSS 2.9%CVE-2018-14281—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interactioEPSS 2.8%CVE-2018-14280—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interactioEPSS 2.8%CVE-2024-38226HIGHMicrosoft Publisher Security Feature Bypass VulnerabilityEPSS 2.7%KEVCVE-2018-0384—A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-bEPSS 2.5%CVE-2023-38157MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 2.5%CVE-2021-32960HIGHRockwell Automation FactoryTalk Services Platform Protection Mechanism FailureEPSS 2.4%CVE-2025-21276HIGHWindows MapUrlToZone Denial of Service VulnerabilityEPSS 2.4%CVE-2022-31479CRITICALRemote Code Execution via command injection of the hostnameEPSS 2.4%CVE-2020-3299MEDIUMMultiple Cisco Products SNORT HTTP Detection Engine File Policy Bypass VulnerabilityEPSS 2.3%