Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2024-1671MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security EPSS 0.8%CVE-2023-39368MEDIUMProtection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable deniEPSS 0.8%CVE-2022-22761HIGHWeb-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it wasEPSS 0.7%CVE-2022-22759CRITICALIf a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document tEPSS 0.7%CVE-2026-26332CRITICALvm2: Sandbox EscapeEPSS 0.7%CVE-2022-43422MEDIUMJenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit where it can be executEPSS 0.7%CVE-2024-28921MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2023-34984HIGHA protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 alloEPSS 0.7%CVE-2024-28903MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2024-30041MEDIUMMicrosoft Bing Search Spoofing VulnerabilityEPSS 0.7%CVE-2023-31273CRITICALProtection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalatioEPSS 0.7%CVE-2024-20665MEDIUMBitLocker Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2026-93605CRITICALvm2 NodeVM before 3.12.1 Remote Code Execution via child_processEPSS 0.7%CVE-2026-57138CRITICALPraisonAI codeMode sandbox escape via Function constructorEPSS 0.7%CVE-2024-28920HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2022-43424MEDIUMJenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can beEPSS 0.7%CVE-2021-31386MEDIUMJunos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks.EPSS 0.7%CVE-2026-93606CRITICALvm2 before 3.12.1 Sandbox Escape via Promise Symbol.speciesEPSS 0.7%CVE-2024-38070HIGHWindows LockDown Policy (WLDP) Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2022-43434MEDIUMJenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generaEPSS 0.7%