Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-92962LOWvm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.jsEPSS 0.2%CVE-2026-0278MEDIUMPrisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on WindowsEPSS 0.2%CVE-2026-11219MEDIUMInappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictioEPSS 0.2%CVE-2025-3770HIGHSMM IDT Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-65339MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.EPSS 0.2%CVE-2026-86909MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass GatekeEPSS 0.2%CVE-2026-40604HIGHClearanceKit: opfilter system extension can be suspended or signalled by a root process, disabling file-access policy enforcementEPSS 0.2%CVE-2025-29864MEDIUMProtection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 beforeEPSS 0.1%CVE-2026-23553LOWx86: incomplete IBPB for vCPU isolationEPSS 0.1%CVE-2025-36938MEDIUMIn U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalatioEPSS 0.1%CVE-2023-20919HIGHIn getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error in the code. This couEPSS 0.1%CVE-2025-43296MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.EPSS 0.1%CVE-2026-54073MEDIUMVeraCrypt: Hidden volume quick format weakens plausible deniabilityEPSS 0.1%CVE-2026-49859MEDIUMDeno: `fetch()` API sandbox bypass via missing DNS resolution checkEPSS 0.1%CVE-2024-0029HIGHIn multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. TEPSS 0.1%CVE-2025-26443HIGHIn parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to EPSS 0.1%CVE-2025-24835MEDIUMProtection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allEPSS 0.1%CVE-2025-21081LOWProtection mechanism failure for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentEPSS 0.1%CVE-2026-12457MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderEPSS 0.1%CVE-2024-0014HIGHIn startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead toEPSS 0.1%