Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-0097HIGHIn multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead toEPSS 0.1%CVE-2023-30757MEDIUMA vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation PEPSS 0.1%CVE-2026-20755MEDIUMProtection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow an escalation of privilege. UnprivilegeEPSS 0.1%CVE-2026-17919MEDIUMInsufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege eEPSS 0.1%CVE-2026-28757MEDIUMProtection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalationEPSS 0.1%CVE-2026-8009MEDIUMInappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer procEPSS 0.1%CVE-2026-28707MEDIUMProtection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. UEPSS 0.1%CVE-2026-20728MEDIUMProtection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may aEPSS 0.1%CVE-2026-20770MEDIUMProtection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User ApplicatiEPSS 0.1%CVE-2026-24693MEDIUMProtection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow EPSS 0.1%CVE-2025-10905MEDIUMCollision in minifilter driver of Avast Free Antivirus results in disabling of real-time protectionEPSS 0.1%CVE-2026-7932MEDIUMInsufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictiEPSS 0.1%CVE-2025-35968HIGHProtection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of privilege. Startup codeEPSS 0.1%CVE-2024-31328HIGHIn broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on thEPSS 0.1%CVE-2025-13326LOWMattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App StoreEPSS 0.1%CVE-2026-49881HIGHIn serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could leEPSS 0.1%CVE-2026-7913HIGHInsufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilegeEPSS 0.1%CVE-2026-86909MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass GatekeEPSS 0.1%CVE-2025-48605HIGHIn multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead EPSS 0.1%CVE-2025-48602HIGHIn exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic erroEPSS 0.1%