Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-20906MEDIUMProtection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an EPSS 0.2%CVE-2026-11219MEDIUMInappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictioEPSS 0.2%CVE-2026-54577LOWmport audit can inspect the wrong package when options are presentEPSS 0.2%CVE-2026-6774MEDIUMMitigation bypass in the DOM: Security componentEPSS 0.2%CVE-2025-3770HIGHSMM IDT Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-29864MEDIUMProtection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 beforeEPSS 0.1%CVE-2026-56585LOWHCL IEM was affected with the Anti Clickjacking XFrame Options Header MissingEPSS 0.1%CVE-2025-36938MEDIUMIn U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalatioEPSS 0.1%CVE-2026-7937LOWInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2026-30904LOWProtection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of inforEPSS 0.1%CVE-2023-20919HIGHIn getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error in the code. This couEPSS 0.1%CVE-2025-43296MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.EPSS 0.1%CVE-2026-49859MEDIUMDeno: `fetch()` API sandbox bypass via missing DNS resolution checkEPSS 0.1%CVE-2024-0029HIGHIn multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. TEPSS 0.1%CVE-2026-71858MEDIUMNotepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command ExecutionEPSS 0.1%CVE-2026-84578HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app EPSS 0.1%CVE-2025-24835MEDIUMProtection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allEPSS 0.1%CVE-2025-21081LOWProtection mechanism failure for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentEPSS 0.1%CVE-2024-0014HIGHIn startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead toEPSS 0.1%CVE-2025-26443HIGHIn parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to EPSS 0.1%