Falhas do tipo CWE-494

187 resultados

Elevação de privilégio

A aplicação não valida corretamente permissões ou contexto de segurança, permitindo que um usuário com privilégios baixos execute ações reservadas a administradores ou usuários com acesso mais elevado. É perigoso porque quebra o modelo de controle de acesso e expõe funcionalidades críticas.

Exemplo

Um usuário comum consegue acessar a API de administração porque o servidor valida apenas a presença de um token válido, ignorando o campo de 'role' contido nele; ou um programa SUID não revoga permissões root antes de executar código fornecido pelo usuário, permitindo leitura de arquivos sensíveis.

Como mitigar

Implemente verificação rigorosa de permissões em toda ação sensível (autorização não apenas autenticação), use listas de controle de acesso (ACL) explícitas, aplique princípio do menor privilégio e audite chamadas privilegiadas. Teste com usuários em papéis baixos para confirmar bloqueios.

CVE-2023-5592HIGHPhoenix Contact: ProConOs prone to Download of Code Without Integrity CheckEPSS 0.3%CVE-2023-46143HIGHPhoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLCEPSS 0.3%CVE-2026-66398CRITICALphpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIEPSS 0.3%CVE-2026-63696CRITICALDell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privilEPSS 0.3%CVE-2023-37220HIGHSynel Terminals - CWE-494: Download of Code Without Integrity CheckEPSS 0.3%CVE-2026-28500HIGHONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain AttackEPSS 0.3%CVE-2026-9089HIGHThe ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatioEPSS 0.3%CVE-2022-4261MEDIUMRapid7 Nexpose Update Validation IssueEPSS 0.3%CVE-2023-46144MEDIUMPHOENIX CONTACT: PLCnext Control prone to download of code without integrity checkEPSS 0.3%CVE-2025-63434HIGHThe update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts upEPSS 0.3%CVE-2026-30612CRITICALAn issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a EPSS 0.3%CVE-2024-30206HIGHA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.3%CVE-2023-5984HIGH A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be uploaded when an authorizeEPSS 0.3%CVE-2025-31355HIGHA firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially craftEPSS 0.3%CVE-2026-33075CRITICALFastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.ymlEPSS 0.3%CVE-2026-55698HIGHpnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesEPSS 0.3%CVE-2026-65081HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. AEPSS 0.3%CVE-2023-47353HIGHAn issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitraEPSS 0.3%CVE-2025-30199HIGHECOVACS Vacuum and Base Station accept unsigned firmwareEPSS 0.3%CVE-2022-38199MEDIUMBUG-000144172 - Remote file download issue in ArcGIS ServerEPSS 0.3%