Falhas do tipo CWE-1220

115 resultados

Controle de acesso com granularidade insuficiente

Ocorre quando um sistema concede permissões em nível muito amplo, sem distinção entre diferentes tipos de operações, recursos ou usuários. Por exemplo, dar acesso total a um módulo quando o usuário precisava apenas ler dados, ou permitir qualquer ação em uma API sem segregar por funcionalidade. Isso amplifica o dano de uma credencial comprometida ou de um usuário mal-intencionado.

Exemplo

Um sistema de gestão de documentos que permite 'administrador' ou 'usuário', quando na verdade deveria ter papéis como 'leitor', 'editor', 'aprovador' e 'gerenciador de usuários'. Se um atacante compromete uma conta de 'usuário', pode fazer tudo que qualquer outro 'usuário' faz — inclusive deletar documentos críticos que só deveria poder ler.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC) ou atributos (ABAC) com permissões específicas e mínimas: defina exatamente quem pode ler, editar, deletar ou transferir cada tipo de recurso. Revise regularmente essas permissões e remova acessos desnecessários durante offboarding ou mudanças de função.

CVE-2025-35998HIGHMissing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within RinEPSS 0.2%CVE-2025-31961LOWHCL Connections is vulnerable to broken access controlEPSS 0.2%CVE-2025-8306MEDIUMImproper Access Control in Asseco Infomedica PlusEPSS 0.2%CVE-2024-53295HIGHDell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerability. A local maliciousEPSS 0.1%CVE-2025-48514MEDIUMInsufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potEPSS 0.1%CVE-2025-48517MEDIUMInsufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guesEPSS 0.1%CVE-2024-21947HIGHImproper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially reEPSS 0.1%CVE-2024-21971MEDIUMImproper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, rEPSS 0.1%CVE-2026-40145HIGHControl protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utilityEPSS 0.1%CVE-2024-21962HIGHImproper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in pEPSS 0.1%CVE-2021-46747HIGHInsufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to mEPSS 0.1%CVE-2024-33058HIGHInsufficient Granularity of Access Control in CoreEPSS 0.1%CVE-2026-15431HIGHHP Support Assistant – Potential Escalation of PrivilegeEPSS 0.1%CVE-2026-20107MEDIUMCisco Application Policy Infrastructure Controller Denial of Service VulnerabilityEPSS 0.1%CVE-2025-31938MEDIUMInsufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an EPSS 0.1%