Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-47209HIGHvm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chainEPSS 0.3%CVE-2022-42848HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. EPSS 0.3%CVE-2026-74790CRITICALScriban before 7.0.0 MemberFilter Bypass via TemplateContext CacheEPSS 0.3%CVE-2025-50325MEDIUMBandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-WEPSS 0.3%CVE-2026-79686HIGHDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploEPSS 0.3%CVE-2026-47139HIGHvm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_serverEPSS 0.3%CVE-2026-92079CRITICALMitigation bypass in the Widget: Win32 componentEPSS 0.3%CVE-2026-79919MEDIUMMaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)EPSS 0.3%CVE-2026-54694CRITICALNationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account TakeoverEPSS 0.3%CVE-2026-92057CRITICALMitigation bypass in the Enterprise Policies componentEPSS 0.3%CVE-2026-16407CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.3%CVE-2024-25744HIGHIn the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tEPSS 0.3%CVE-2022-48219MEDIUMPotential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusioEPSS 0.3%CVE-2026-26994MEDIUMuTLS ServerHellos are accepted without checking TLS 1.3 downgrade canariesEPSS 0.3%CVE-2022-46329HIGHProtection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation ofEPSS 0.3%CVE-2026-17856CRITICALInappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renEPSS 0.3%CVE-2026-48033HIGHHulumi: Policy packs bypassed by a forged Pulumi-URN logical nameEPSS 0.3%CVE-2026-17865CRITICALInappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2025-50897MEDIUMA vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translationsEPSS 0.3%CVE-2026-50564CRITICALFission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escapeEPSS 0.3%