Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2025-58406MEDIUMLack of HTTP Response HeadersEPSS 0.2%CVE-2023-34427MEDIUMProtection mechanism failure in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an autEPSS 0.2%CVE-2026-14092MEDIUMInsufficient policy enforcement in Privacy in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to lEPSS 0.2%CVE-2022-20805MEDIUMCisco Umbrella Secure Web Gateway File Decryption Bypass VulnerabilityEPSS 0.2%CVE-2026-11264MEDIUMPolicy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policyEPSS 0.2%CVE-2026-8563MEDIUMInsufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass naEPSS 0.2%CVE-2026-28912HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.6. EPSS 0.2%CVE-2026-11260MEDIUMInappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security polEPSS 0.2%CVE-2026-47624MEDIUMNVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of EPSS 0.2%CVE-2026-49316MEDIUMIndian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdownEPSS 0.2%CVE-2026-55487HIGHpnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycleEPSS 0.2%CVE-2026-70444MEDIUMA missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission tEPSS 0.2%CVE-2025-46358HIGHEmerson ValveLink Products Protection Mechanism FailureEPSS 0.2%CVE-2026-13601HIGHYelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applicationsEPSS 0.2%CVE-2022-41984MEDIUMProtection mechanism failure for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and DecembeEPSS 0.2%CVE-2026-8583MEDIUMInsufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2024-36242HIGHProtection mechanism failure in the SPP for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of priEPSS 0.2%CVE-2026-17936MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage inEPSS 0.2%CVE-2026-11247LOWInsufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-oriEPSS 0.2%CVE-2026-11234MEDIUMInappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendeEPSS 0.2%