Fallos del tipo CWE-693

833 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2018-0094—A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a EPSS 2.3%CVE-2020-3315MEDIUMMultiple Cisco Products Snort HTTP Detection Engine File Policy Bypass VulnerabilityEPSS 2.2%CVE-2023-33150CRITICALMicrosoft Office Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2024-26163MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2021-1224MEDIUMMultiple Cisco Products Snort TCP Fast Open File Policy Bypass VulnerabilityEPSS 2.0%CVE-2021-1223MEDIUMMultiple Cisco Products Snort HTTP Detection Engine File Policy Bypass VulnerabilityEPSS 2.0%CVE-2025-21217MEDIUMWindows NTLM Spoofing VulnerabilityEPSS 1.9%CVE-2022-21626MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions tEPSS 1.9%CVE-2018-0333—A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to byEPSS 1.9%CVE-2018-0326—A vulnerability in the web UI of Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to conduct a cross-frameEPSS 1.8%CVE-2025-33050HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 1.8%CVE-2025-32725HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 1.8%CVE-2018-0198—A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitiEPSS 1.7%CVE-2019-1833MEDIUMCisco Firepower Threat Defense Software SSL/TLS Policy Bypass VulnerabilityEPSS 1.7%CVE-2019-1832MEDIUMCisco Firepower Threat Defense Software Detection Engine Policy Bypass VulnerabilityEPSS 1.6%CVE-2025-27472MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 1.6%CVE-2024-38092HIGHAzure CycleCloud Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2024-38180HIGHWindows SmartScreen Security Feature Bypass VulnerabilityEPSS 1.6%CVE-2022-36085HIGHOPA Compiler: Bypass of WithUnsafeBuiltins using `with` keyword to mock functionsEPSS 1.6%CVE-2023-32006HIGHThe use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition foEPSS 1.5%