Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-8585HIGHInappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2026-5276MEDIUMInsufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitiveEPSS 0.3%CVE-2026-16407CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.3%CVE-2024-25744HIGHIn the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tEPSS 0.3%CVE-2022-48219MEDIUMPotential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusioEPSS 0.3%CVE-2022-46329HIGHProtection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation ofEPSS 0.3%CVE-2026-60166LOWVulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploitEPSS 0.3%CVE-2025-50897MEDIUMA vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translationsEPSS 0.3%CVE-2026-17923MEDIUMPolicy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafteEPSS 0.3%CVE-2026-60164LOWVulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploitEPSS 0.3%CVE-2026-78552MEDIUMValidation Bypass in Okta Access Gateway Custom DirectivesEPSS 0.3%CVE-2026-3472LOWMarkdown image rendering bypass in AI bot tool result posts in MattermostEPSS 0.3%CVE-2020-7277MEDIUMMcAfee processes not protectedEPSS 0.3%CVE-2026-49316MEDIUMIndian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdownEPSS 0.3%CVE-2026-28627MEDIUMIn btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote inEPSS 0.3%CVE-2026-13886MEDIUMInsufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content secEPSS 0.3%CVE-2026-13904MEDIUMInappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation EPSS 0.3%CVE-2024-44122HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, macOS EPSS 0.3%CVE-2026-17899HIGHInsufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a maEPSS 0.3%CVE-2024-39836MEDIUMMunged email address used for password resets and notificationsEPSS 0.3%