Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-0293MEDIUMPrisma Access Agent: Anti-Tamper Protection Bypass on WindowsEPSS 0.1%CVE-2025-27700HIGHThere is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no adEPSS 0.1%CVE-2026-40604HIGHClearanceKit: opfilter system extension can be suspended or signalled by a root process, disabling file-access policy enforcementEPSS 0.1%CVE-2026-0306MEDIUMPrisma Access Agent: EndPoint DLP Bypass Vulnerability on WindowsEPSS 0.1%CVE-2026-0012MEDIUMIn setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This coulEPSS 0.1%CVE-2025-48635HIGHIn multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. ThiEPSS 0.1%CVE-2026-57012HIGHIn the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of pEPSS 0.1%CVE-2025-0089HIGHIn multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalatEPSS 0.1%CVE-2026-58767MEDIUMIn multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to locEPSS 0.1%CVE-2023-21024HIGHIn maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error. This could lead to local escalation ofEPSS 0.1%CVE-2022-20464MEDIUMIn various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. EPSS 0.1%CVE-2025-48653HIGHIn loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could EPSS 0.1%CVE-2024-49720HIGHIn multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic eEPSS 0.1%CVE-2025-32331HIGHIn showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This couEPSS 0.1%CVE-2025-48531HIGHIn getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to loEPSS 0.1%CVE-2026-0017HIGHIn onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could leadEPSS 0.1%CVE-2025-26464HIGHIn executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. ThisEPSS 0.1%CVE-2025-48522HIGHIn setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code.EPSS 0.1%CVE-2025-52643MEDIUMHCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environmentEPSS 0.1%CVE-2025-22433HIGHIn canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work ProfEPSS 0.1%