Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2022-22152HIGHContrail Service Orchestration: Tenants able to see other tenants policies via REST API interfaceEPSS 0.8%CVE-2026-62902MEDIUM.NET Information Disclosure VulnerabilityEPSS 0.8%CVE-2023-32493HIGH Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exEPSS 0.8%CVE-2025-21211MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2023-4039MEDIUMGCC's-fstack-protector fails to guard dynamically-sized local variables on AArch64EPSS 0.8%CVE-2019-3586HIGHMcAfee Endpoint Security firewall not always acting on GTI lookup resultsEPSS 0.8%CVE-2014-125107MEDIUMCorveda PHPSandbox String protection mechanismEPSS 0.8%CVE-2026-24425HIGHTwig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterfaceEPSS 0.8%CVE-2024-1671MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security EPSS 0.8%CVE-2023-39368MEDIUMProtection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable deniEPSS 0.8%CVE-2022-22759CRITICALIf a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document tEPSS 0.7%CVE-2022-22761HIGHWeb-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it wasEPSS 0.7%CVE-2026-92934CRITICALvm2 before 3.11.8 Sandbox Escape RCE via AggregateErrorEPSS 0.7%CVE-2024-28921MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2023-34984HIGHA protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 alloEPSS 0.7%CVE-2024-28903MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2024-30041MEDIUMMicrosoft Bing Search Spoofing VulnerabilityEPSS 0.7%CVE-2023-31273CRITICALProtection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalatioEPSS 0.7%CVE-2024-20665MEDIUMBitLocker Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2024-28920HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%