Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2024-0014HIGHIn startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead toEPSS 0.1%CVE-2024-36315MEDIUMImproper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensEPSS 0.1%CVE-2026-57012HIGHIn the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of pEPSS 0.1%CVE-2026-20667HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4EPSS 0.1%CVE-2026-0011HIGHIn enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the codeEPSS 0.1%CVE-2026-82474HIGHSudo through 1.9.17p2 Intercept Policy Bypass via execveatEPSS 0.1%CVE-2026-1232MEDIUMAnti-Tamper Bypass in BeyondTrust Privilege Management for WindowsEPSS 0.1%CVE-2025-30431MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A maliciEPSS 0.1%CVE-2025-24284HIGHThis issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be ableEPSS 0.1%CVE-2025-26402MEDIUMProtection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged softEPSS 0.1%CVE-2026-12214HIGHQihoo 360 Total Security Nucleus Engine Monitoring Logic RpcStringBindingComposeW protection mechanismEPSS 0.1%CVE-2025-24848MEDIUMProtection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow anEPSS 0.1%CVE-2026-91796MEDIUMFoxit PDF Editor/Reader importIcon NTLM Response Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-71858MEDIUMNotepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command ExecutionEPSS 0.1%CVE-2026-0097HIGHIn multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead toEPSS 0.1%CVE-2023-30757MEDIUMA vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation PEPSS 0.1%CVE-2025-10905MEDIUMCollision in minifilter driver of Avast Free Antivirus results in disabling of real-time protectionEPSS 0.1%CVE-2025-35968HIGHProtection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of privilege. Startup codeEPSS 0.1%CVE-2024-31328HIGHIn broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on thEPSS 0.1%CVE-2025-13326LOWMattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App StoreEPSS 0.1%