Falhas do tipo CWE-602

174 resultados

Confiança inadequada em mecanismo de proteção implementado no cliente

O servidor delega uma função de segurança para o cliente executar, assumindo que o cliente vai implementar ou respeitar essa proteção. Na prática, o atacante controla o cliente e pode contornar ou desabilitar o mecanismo, comprometendo a segurança do servidor. É um erro fundamental de arquitetura: nunca confie em validações ou controles que rodem no lado do cliente.

Exemplo

Um servidor web que valida permissões apenas via JavaScript no navegador, permitindo ao usuário editar o HTML/JS localmente e contornar as restrições. Ou uma API que depende do cliente para não enviar dados além de um limite, sem validar no servidor.

Como mitigar

Implemente todas as validações críticas de segurança (autenticação, autorização, limite de taxa, validação de entrada) obrigatoriamente no servidor. Trate o cliente como potencialmente adversário e nunca confie em nada que venha dele sem re-validar no backend.

CVE-2025-32808HIGHW. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because EPSS 0.4%CVE-2025-1838MEDIUMIBM Cloud Pak for Business Automation denial of serviceEPSS 0.4%CVE-2025-53969HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Client-Side Enforcement of Server-Side SecurityEPSS 0.4%CVE-2025-56694MEDIUMClient-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to view password-protectEPSS 0.4%CVE-2024-32685MEDIUMWordPress WP Ultimate Review plugin <= 2.2.5 - Review Score Manipulation vulnerabilityEPSS 0.4%CVE-2023-20171MEDIUMCisco Identity Services Engine Arbitrary File Delete and File Read VulnerabilitiesEPSS 0.4%CVE-2026-30783MEDIUMRustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL PoliciesEPSS 0.4%CVE-2023-30955MEDIUMFoundry workspace-server Developer Mode Authorization BypassEPSS 0.4%CVE-2023-20106MEDIUMCisco Identity Services Engine Arbitrary File Delete and File Read VulnerabilitiesEPSS 0.4%CVE-2026-84110MEDIUMReleasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side securityEPSS 0.4%CVE-2026-63301HIGHDenial of Service in Quick.CMSEPSS 0.4%CVE-2025-36327MEDIUMVulnerabilities found in Watson Data IntelligenceEPSS 0.4%CVE-2021-36338MEDIUMUnisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentiallyEPSS 0.4%CVE-2025-25497HIGHAn issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "AccEPSS 0.4%CVE-2026-0808MEDIUMSpin Wheel <= 2.1.0 - Unauthenticated Client-Side Prize Manipulation via 'prize_index' ParameterEPSS 0.4%CVE-2026-17756MEDIUMInsufficient policy enforcement in Presentation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrEPSS 0.4%CVE-2024-20476MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2024-32521MEDIUMWordPress Zero Spam for WordPress plugin <= 5.5.6 - Bypass Spam Protection vulnerabilityEPSS 0.4%CVE-2026-13919MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2026-13930MEDIUMInsufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictionsEPSS 0.3%