Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-12302MEDIUMMitigation bypass in the DOM: Security componentEPSS 0.2%CVE-2023-22655MEDIUMProtection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a EPSS 0.2%CVE-2026-9115MEDIUMInsufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origiEPSS 0.2%CVE-2026-79006MEDIUMProtection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy EPSS 0.2%CVE-2026-56585LOWHCL IEM was affected with the Anti Clickjacking XFrame Options Header MissingEPSS 0.2%CVE-2026-12316CRITICALMitigation bypass in the DOM: Security componentEPSS 0.2%CVE-2026-92030MEDIUMMitigation bypass in the DOM: Copy & Paste and Drag & Drop componentEPSS 0.2%CVE-2025-22429CRITICALIn multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalatiEPSS 0.2%CVE-2026-11282CRITICALInsufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially performEPSS 0.2%CVE-2026-5900MEDIUMPolicy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a cEPSS 0.2%CVE-2025-67485MEDIUMHTTP/HTTPS Traffic Interception Bypass in mad-proxyEPSS 0.2%CVE-2026-11248HIGHInappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictiEPSS 0.2%CVE-2026-9116MEDIUMInsufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin EPSS 0.2%CVE-2026-17936MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage inEPSS 0.2%CVE-2026-11170HIGHInappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level prEPSS 0.2%CVE-2026-7946MEDIUMInsufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker EPSS 0.2%CVE-2026-49325MEDIUMIndian Scout Bobber 2025 WCM voltage-based shutdownEPSS 0.2%CVE-2025-8656MEDIUMKenwood DMX958XR Protection Mechanism Failure Software Downgrade VulnerabilityEPSS 0.2%CVE-2021-3453MEDIUMSome Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker wiEPSS 0.2%CVE-2026-8563MEDIUMInsufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass naEPSS 0.2%