Falhas do tipo CWE-636

56 resultados

Degradação para estado menos seguro em caso de erro

É quando o software, ao encontrar uma falha ou erro, recua automaticamente para um modo de operação menos seguro — como criptografia mais fraca, controle de acesso permissivo ou autenticação relaxada. O perigo: o atacante pode forçar o erro para explorar o fallback inseguro, transformando uma falha em brecha de segurança.

Exemplo

Um serviço tenta conectar com TLS 1.3, mas se falhar recai para SSL 3.0. Ou um sistema de autenticação multi-fator que, se o segundo fator não responder, aceita apenas a senha — permitindo ao atacante apenas bloquear o segundo fator para contornar a proteção.

Como mitigar

Nunca faça fallback para opções menos seguras: ou a operação funciona no nível de segurança exigido, ou ela falha explicitamente. Se há degradação inevitável (ex: compatibilidade), ela deve ser explícita, auditada e nunca automática em face de erro.

CVE-2024-43532HIGHRemote Registry Service Elevation of Privilege VulnerabilityEPSS 12.0%CVE-2023-28840HIGHmoby/moby's dockerd daemon encrypted overlay network may be unauthenticatedEPSS 2.6%CVE-2021-1578HIGHCisco Application Policy Infrastructure Controller Privilege Escalation VulnerabilityEPSS 2.0%CVE-2023-28842MEDIUMmoby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedEPSS 1.4%CVE-2025-21210MEDIUMWindows BitLocker Information Disclosure VulnerabilityEPSS 1.1%CVE-2026-53913CRITICALApache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is acceptedEPSS 1.1%CVE-2024-3729CRITICALFrontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form ManipulationEPSS 0.8%CVE-2026-22034CRITICALSnuffleupagus vulnerable to RCE on instances with upload validation enabled but without the VLD packageEPSS 0.7%CVE-2023-28841MEDIUMmoby/moby's dockerd daemon encrypted overlay network traffic may be unencryptedEPSS 0.7%CVE-2026-40525CRITICALOpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPIEPSS 0.6%CVE-2026-50528HIGH.NET Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-40247HIGHfree5gc UDR improper path validation allows unauthenticated access to Traffic Influence SubscriptionsEPSS 0.5%CVE-2024-8185HIGHVault Vulnerable to Denial of Service When Processing Raft Join RequestsEPSS 0.5%CVE-2026-70452CRITICALrsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution FailureEPSS 0.5%CVE-2026-77866CRITICALSSRF protection bypass in safeurl via IPv6 addresses and unresolvable hostsEPSS 0.5%CVE-2026-73421CRITICALNextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)EPSS 0.5%CVE-2026-68746HIGHLivebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated accessEPSS 0.4%CVE-2026-54762MEDIUMTraefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution failsEPSS 0.4%CVE-2026-40248HIGHfree5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence SubscriptionsEPSS 0.4%CVE-2026-53459CRITICALBambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpointsEPSS 0.4%