Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2021-33081HIGHProtection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially enable information disEPSS 0.2%CVE-2026-22707MEDIUMStrapi Upload Plugin MIME Validation Bypass via Content APIEPSS 0.2%CVE-2024-20286MEDIUMCisco NX-OS Software Python Parser Escape VulnerabilityEPSS 0.2%CVE-2024-20284MEDIUMCisco NX-OS Software Python Parser Escape VulnerabilityEPSS 0.2%CVE-2026-8009MEDIUMInappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2026-94251MEDIUMApache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resourceEPSS 0.2%CVE-2026-17776MEDIUMPolicy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to poteEPSS 0.2%CVE-2026-79298HIGHAn issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrarEPSS 0.2%CVE-2026-35408HIGHDirectus is Missing Cross-Origin Opener PolicyEPSS 0.2%CVE-2025-59849MEDIUMHCL BigFix Remote Control is vulnerable to an insecure CSP configurationEPSS 0.2%CVE-2026-12031HIGHInappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the EPSS 0.2%CVE-2025-48571MEDIUMIn multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. ThiEPSS 0.2%CVE-2023-25945MEDIUMProtection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escaEPSS 0.2%CVE-2026-30904LOWProtection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of inforEPSS 0.2%CVE-2024-36287LOWBypass of TCC restrictions on macOSEPSS 0.2%CVE-2025-31189HIGHA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS VenturaEPSS 0.2%CVE-2023-42938HIGHA logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevateEPSS 0.2%CVE-2025-31244HIGHA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out ofEPSS 0.2%CVE-2026-11292MEDIUMInsufficient policy enforcement in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policyEPSS 0.2%CVE-2023-25080MEDIUMProtection mechanism failure in some Intel(R) Distribution of OpenVINO toolkit software before version 2023.0.0 may allow an authenticated uEPSS 0.2%