Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-39419LOWMaxKB: Sandbox Result Validation Bypass via Tool Output SpoofingEPSS 0.2%CVE-2026-7963HIGHInappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2026-48721HIGHWarp: Env-var prefixes can lead to denylisted command autoexecutionEPSS 0.2%CVE-2025-41224HIGHA vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.10.0), REPSS 0.2%CVE-2026-9116MEDIUMInsufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin EPSS 0.2%CVE-2026-8571HIGHInsufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised theEPSS 0.2%CVE-2026-56087MEDIUMDell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could EPSS 0.2%CVE-2026-43670HIGHA Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 1EPSS 0.2%CVE-2024-56182HIGHA vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21EPSS 0.2%CVE-2024-56181HIGHA vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32AEPSS 0.2%CVE-2025-52615LOWHCL Unica Platform is impacted by misconfigured security related HTTP headersEPSS 0.2%CVE-2026-28627MEDIUMIn btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote inEPSS 0.2%CVE-2025-24834MEDIUMProtection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow anEPSS 0.2%CVE-2026-59277LOWSpring Security InetAddressMatchers Incomplete Internal Network ClassificationEPSS 0.2%CVE-2026-17923MEDIUMPolicy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafteEPSS 0.2%CVE-2025-24523MEDIUMProtection mechanism failure for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an auEPSS 0.2%CVE-2026-86894HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandboEPSS 0.2%CVE-2026-12438HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2026-58704HIGHIn Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escEPSS 0.2%CVE-2026-11174MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renEPSS 0.2%