Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2025-26464HIGHIn executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. ThisEPSS 0.1%CVE-2025-48522HIGHIn setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code.EPSS 0.1%CVE-2026-58726MEDIUMIn FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of pEPSS 0.1%CVE-2026-7932MEDIUMInsufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictiEPSS 0.1%CVE-2026-57006MEDIUMIn acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with SystemEPSS 0.1%CVE-2025-48653HIGHIn loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could EPSS 0.1%CVE-2026-56982HIGHIn VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with SysteEPSS 0.1%CVE-2024-49720HIGHIn multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic eEPSS 0.1%CVE-2026-0017HIGHIn onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could leadEPSS 0.1%CVE-2025-22433HIGHIn canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work ProfEPSS 0.1%CVE-2025-52643MEDIUMHCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environmentEPSS 0.1%CVE-2025-48546HIGHIn checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This couldEPSS 0.1%CVE-2025-22427HIGHIn onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due tEPSS 0.1%CVE-2026-28660LOWIn getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local informatEPSS 0.1%CVE-2025-26444HIGHIn onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the defaultEPSS 0.1%CVE-2025-26458HIGHIn multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. ThisEPSS 0.1%CVE-2025-22437HIGHIn setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in EPSS 0.1%CVE-2025-22434HIGHIn handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could leaEPSS 0.1%CVE-2025-26431HIGHIn setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logicEPSS 0.1%CVE-2026-45521LOWIn openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local inEPSS 0.1%