Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2021-3453MEDIUMSome Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker wiEPSS 0.2%CVE-2025-8656MEDIUMKenwood DMX958XR Protection Mechanism Failure Software Downgrade VulnerabilityEPSS 0.2%CVE-2026-14076MEDIUMInsufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security poliEPSS 0.2%CVE-2025-43330HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bEPSS 0.2%CVE-2026-90957MEDIUMMISP: Stored XSS via Inline-Served SVG Organisation Logos and Report PicturesEPSS 0.2%CVE-2026-20277HIGHCisco IOS XR Software Security Hardening Release: September 2026EPSS 0.2%CVE-2020-12954—A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPIEPSS 0.2%CVE-2026-44451CRITICALLumiverse: TSX component sandbox escape via DOM ref and string-split identifier bypassEPSS 0.2%CVE-2026-20331CRITICALCisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure VulnerabilitiesEPSS 0.2%CVE-2026-11206MEDIUMInsufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin dataEPSS 0.2%CVE-2026-10174MEDIUMAider-AI Aider Pre-commit Hook args.py protection mechanismEPSS 0.2%CVE-2026-13876MEDIUMInappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypaEPSS 0.2%CVE-2026-45227HIGHHeym < 0.0.21 Sandbox Escape via Python IntrospectionEPSS 0.2%CVE-2026-17931MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictionsEPSS 0.2%CVE-2022-48611HIGHA logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevateEPSS 0.2%CVE-2026-22723MEDIUMUAA User Token Revocation logic errorEPSS 0.2%CVE-2026-9115MEDIUMInsufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origiEPSS 0.2%CVE-2025-31224HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An aEPSS 0.2%CVE-2026-92039MEDIUMMitigation bypass in the DOM: Notifications componentEPSS 0.2%CVE-2026-12027CRITICALInappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the rendererEPSS 0.2%