Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-56087MEDIUMDell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could EPSS 0.2%CVE-2024-56181HIGHA vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32AEPSS 0.2%CVE-2026-24868MEDIUMMitigation bypass in the Privacy: Anti-Tracking componentEPSS 0.2%CVE-2024-56182HIGHA vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21EPSS 0.2%CVE-2025-52615LOWHCL Unica Platform is impacted by misconfigured security related HTTP headersEPSS 0.2%CVE-2025-24834MEDIUMProtection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow anEPSS 0.2%CVE-2025-24523MEDIUMProtection mechanism failure for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an auEPSS 0.2%CVE-2026-11174MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renEPSS 0.2%CVE-2026-12438HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2026-90950MEDIUMPaid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration FormEPSS 0.2%CVE-2026-17659MEDIUMInappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2026-7952MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2024-45835LOWInsufficient Electron Fuses ConfigurationEPSS 0.2%CVE-2025-46281HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An appEPSS 0.2%CVE-2025-55249LOWHCL AION is affected by a Missing Security Response Headers vulnerability.EPSS 0.2%CVE-2025-46291MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An app may bypass GatekEPSS 0.2%CVE-2026-14440HIGHCloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA recordsEPSS 0.2%CVE-2026-8004MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2026-11288MEDIUMInsufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a craEPSS 0.2%CVE-2025-12909MEDIUMInsufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via EPSS 0.2%