Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2024-20673HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 1.2%CVE-2026-24781CRITICALvm2: Sandbox Breakout Through InspectEPSS 1.2%CVE-2018-0297—A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an unauthenticated, remote attacker to bypassEPSS 1.2%CVE-2018-0244—A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a confiEPSS 1.2%CVE-2018-0243—A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a confiEPSS 1.2%CVE-2018-0254—A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configuEPSS 1.2%CVE-2025-24061HIGHWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2026-21669CRITICALA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.EPSS 1.2%CVE-2026-23830CRITICALSandboxJS has Sandbox Escape via Unprotected AsyncFunction ConstructorEPSS 1.2%CVE-2018-0138—A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file poEPSS 1.2%CVE-2024-30370MEDIUMRARLAB WinRAR Mark-Of-The-Web Bypass VulnerabilityEPSS 1.2%CVE-2026-53710CRITICALMCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_serverEPSS 1.1%CVE-2026-41316HIGHERB has an @_init deserialization guard bypass via def_module / def_method / def_classEPSS 1.1%CVE-2022-39266CRITICALisolated-vm has vulnerable CachedDataOptions in APIEPSS 1.1%CVE-2022-3056MEDIUMInsufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass conteEPSS 1.1%CVE-2022-20738MEDIUMCisco Umbrella Secure Web Gateway File Inspection Bypass VulnerabilityEPSS 1.1%CVE-2021-1494MEDIUMMultiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker tEPSS 1.1%CVE-2023-25765CRITICALIn Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowiEPSS 1.1%CVE-2022-3044MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renEPSS 1.1%CVE-2024-20926MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ScriptiEPSS 1.0%