Falhas do tipo CWE-648

67 resultados

Uso incorreto de APIs privilegiadas

Ocorre quando o código invoca funções do sistema operacional ou framework com poderes elevados (root, admin, capacidades especiais) sem validação adequada dos parâmetros de entrada, ou sem verificar se o contexto realmente justifica esse privilégio. O atacante explora a confiança da aplicação em dados não sanitizados para executar operações que deveriam estar protegidas.

Exemplo

Uma aplicação web chama execSQL() com privilégios de administrador de banco de dados, passando diretamente um parâmetro do usuário sem validação. Alguém injeta SQL malicioso que modifica dados críticos ou deleta tabelas — tudo com poder administrativo que não deveria ter sido necessário.

Como mitigar

Use APIs com privilégios mínimos: execute operações críticas com permissões apenas suficientes para aquela tarefa. Sempre sanitize e valide entrada de usuário antes de usá-la em chamadas privilegiadas. Implemente controle de acesso baseado em roles (RBAC) para garantir que escalação de privilégio seja explícita e limitada.

CVE-2026-20122MEDIUMCisco Catalyst SD-WAN Manager Arbitrary File Overwrite VulnerabilityEPSS 24.6%KEVCVE-2019-14813HIGHA flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged EPSS 11.4%CVE-2024-8785CRITICALWhatsUp Gold Registry Overwrite Remote Code Execution VulnerabilityEPSS 9.7%CVE-2025-54766MEDIUMKL-001-2025-012: Xorux XorMon-NG Read Only User Export Device Configuration Exposing Sensitive InformationEPSS 6.9%CVE-2025-54765MEDIUMKL-001-2025-013: Xorux XorMon-NG Web Application Privilege Escalation to AdministratorEPSS 6.9%CVE-2025-54767MEDIUMKL-001-2025-014: Xorux LPAR2RRD Read Only User Denial of ServiceEPSS 5.3%CVE-2019-1010178Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component iEPSS 4.6%CVE-2025-54768MEDIUMKL-001-2025-015: Xorux LPAR2RRD Read Only User Log Download Exposing Sensitive InformationEPSS 4.0%CVE-2019-14811HIGHA flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileEPSS 3.7%CVE-2019-14869HIGHA flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its priviEPSS 3.4%CVE-2022-2023CRITICALIncorrect Use of Privileged APIs in polonel/trudeskEPSS 3.0%CVE-2025-54769HIGHKL-001-2025-016: Xorux LPAR2RRD File Upload Directory TraversalEPSS 3.0%CVE-2019-3838HIGHIt was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PoEPSS 2.6%CVE-2019-3835HIGHIt was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScriptEPSS 2.6%CVE-2019-14812HIGHA flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privilegEPSS 2.5%CVE-2019-10216HIGHIn ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAEPSS 2.3%CVE-2019-14817HIGHA flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privEPSS 2.0%CVE-2019-3839HIGHIt was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially EPSS 1.8%CVE-2022-20956HIGHA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker EPSS 1.3%CVE-2024-11068CRITICALD-Link DSL6740C - Incorrect Use of Privileged APIsEPSS 1.2%