Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-17919MEDIUMInsufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege eEPSS 0.2%CVE-2026-20906MEDIUMProtection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an EPSS 0.2%CVE-2026-21400MEDIUMProtection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring 3: User Applications may allow an escalEPSS 0.2%CVE-2026-28757MEDIUMProtection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalationEPSS 0.2%CVE-2026-20770MEDIUMProtection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User ApplicatiEPSS 0.2%CVE-2025-52609LOWHCL iControl was affected by Missing Security Headers vulnerability.EPSS 0.2%CVE-2026-21387MEDIUMProtection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilegeEPSS 0.2%CVE-2026-20755MEDIUMProtection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow an escalation of privilege. UnprivilegeEPSS 0.2%CVE-2026-20903MEDIUMProtection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation EPSS 0.2%CVE-2026-28707MEDIUMProtection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. UEPSS 0.2%CVE-2026-20728MEDIUMProtection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may aEPSS 0.2%CVE-2026-24693MEDIUMProtection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow EPSS 0.2%CVE-2025-67460HIGHZoom Rooms for Windows - Software Downgrade Protection Mechanism FailureEPSS 0.2%CVE-2026-15528MEDIUMlamaalrajih kicad-mcp path_validator.py protection mechanismEPSS 0.2%CVE-2026-84559MEDIUMA permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.EPSS 0.2%CVE-2026-54577LOWmport audit can inspect the wrong package when options are presentEPSS 0.2%CVE-2023-42918HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to cEPSS 0.2%CVE-2026-28900MEDIUMA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2026-28849MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciouEPSS 0.2%CVE-2026-84570MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app EPSS 0.2%