Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2018-0094—A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a EPSS 2.3%CVE-2020-3315MEDIUMMultiple Cisco Products Snort HTTP Detection Engine File Policy Bypass VulnerabilityEPSS 2.2%CVE-2023-33150CRITICALMicrosoft Office Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2024-26163MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2021-1224MEDIUMMultiple Cisco Products Snort TCP Fast Open File Policy Bypass VulnerabilityEPSS 2.0%CVE-2021-1223MEDIUMMultiple Cisco Products Snort HTTP Detection Engine File Policy Bypass VulnerabilityEPSS 2.0%CVE-2022-21626MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions tEPSS 1.9%CVE-2025-21217MEDIUMWindows NTLM Spoofing VulnerabilityEPSS 1.9%CVE-2018-0333—A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to byEPSS 1.9%CVE-2025-33050HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 1.8%CVE-2018-0326—A vulnerability in the web UI of Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to conduct a cross-frameEPSS 1.8%CVE-2025-32725HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 1.8%CVE-2018-0198—A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitiEPSS 1.7%CVE-2019-1833MEDIUMCisco Firepower Threat Defense Software SSL/TLS Policy Bypass VulnerabilityEPSS 1.7%CVE-2019-1832MEDIUMCisco Firepower Threat Defense Software Detection Engine Policy Bypass VulnerabilityEPSS 1.6%CVE-2025-27472MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 1.6%CVE-2024-38092HIGHAzure CycleCloud Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2024-38180HIGHWindows SmartScreen Security Feature Bypass VulnerabilityEPSS 1.6%CVE-2022-36085HIGHOPA Compiler: Bypass of WithUnsafeBuiltins using `with` keyword to mock functionsEPSS 1.6%CVE-2023-32006HIGHThe use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition foEPSS 1.5%