Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2024-33903MEDIUMIn CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part because the collision EPSS 0.5%CVE-2026-57136HIGHPraisonAI SandboxExecutor allowedCommands bypass via shell chainingEPSS 0.5%CVE-2026-25115CRITICALn8n is vulnerable to Python sandbox escapeEPSS 0.5%CVE-2024-43645MEDIUMWindows Defender Application Control (WDAC) Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-43584HIGHWindows Scripting Engine Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2025-44090HIGHAn issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.5%CVE-2022-33942HIGHProtection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user to potentially enable escalatEPSS 0.5%CVE-2024-0101HIGHNVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enEPSS 0.5%CVE-2022-42801HIGHA logic issue was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS EPSS 0.5%CVE-2025-44089HIGHAn issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.5%CVE-2024-23499HIGHProtection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before versEPSS 0.5%CVE-2026-76827MEDIUMSearch-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)EPSS 0.5%CVE-2026-50545CRITICALFission Environment CRD PodSpec Injection Leading to Node Escape and Cluster TakeoverEPSS 0.5%CVE-2024-56326MEDIUMJinja has a sandbox breakout through indirect reference to format methodEPSS 0.5%CVE-2023-3089HIGHOcp & fips modeEPSS 0.5%CVE-2026-84811HIGHagentverus-scanner Companion Code Analysis Bypass via Excluded Python BytecodeEPSS 0.5%CVE-2023-4466LOWPoly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanismEPSS 0.5%CVE-2026-57280HIGHJenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed foEPSS 0.5%CVE-2026-21668HIGHA vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.EPSS 0.5%CVE-2026-79686HIGHDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploEPSS 0.5%