Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-28584MEDIUMIn createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the EPSS 0.1%CVE-2025-36898HIGHThere is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additEPSS 0.1%CVE-2025-36905HIGHIn gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local EPSS 0.1%CVE-2025-26439HIGHIn getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead ofEPSS 0.1%CVE-2026-0118HIGHIn oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalation of privilege withEPSS 0.1%CVE-2025-48554MEDIUMIn handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the coEPSS 0.1%CVE-2025-48652HIGHIn performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This coulEPSS 0.1%CVE-2026-0045HIGHIn bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. TEPSS 0.1%CVE-2026-0087HIGHIn approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic EPSS 0.1%CVE-2026-0077HIGHIn resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the cEPSS 0.1%CVE-2025-22431MEDIUMIn multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due EPSS 0.1%CVE-2026-0189HIGHIn ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2025-48649HIGHIn multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead toEPSS 0.1%CVE-2026-0186MEDIUMIn ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalEPSS 0.1%CVE-2026-0187MEDIUMIn gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could leadEPSS 0.1%CVE-2026-0084HIGHIn multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This coEPSS 0.1%CVE-2026-0065HIGHIn areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in EPSS 0.1%CVE-2026-100676HIGHstoatchat before 0.15.5 Local Filesystem Read via SVGEPSS —CVE-2025-71424MEDIUMEdgeless Systems Contrast before 1.9.1 Insecure Volume MountEPSS —