Falhas do tipo CWE-701

12 resultados

Fraqueza Introduzida na Fase de Design

É uma categoria genérica que agrupa vulnerabilidades nascidas de decisões arquiteturais ou de design inadequadas, não de erros de implementação. O software é construído sobre premissas inseguras desde o início — seja por falta de validação, controle de acesso deficiente ou fluxos de dados mal planejados — tornando difícil corrigir o problema sem redesenho significativo.

Exemplo

Um sistema que armazena senhas em texto plano porque a arquitetura original não previa criptografia, ou uma API que confia cegamente em headers HTTP porque ninguém pensou em autenticação real durante o planejamento inicial.

Como mitigar

Revisar a arquitetura e fluxos de dados na fase de design; implementar validação, autenticação e autorização como fundações, não como adições; realizar threat modeling antes de codificar. Se já em produção, replanejar módulos críticos e aplicar mitigações em camadas (WAF, rate limiting, isolamento de rede) enquanto se executa o redesign.

CVE-2023-6791MEDIUMPAN-OS: Plaintext Disclosure of External System Integration CredentialsEPSS 0.6%CVE-2022-48517Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2021-46895Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability wilEPSS 0.4%CVE-2021-46892Encryption bypass vulnerability in Maintenance mode. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.3%CVE-2024-57962MEDIUMVulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this vulnerability may affEPSS 0.2%CVE-2023-52954MEDIUMVulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availabiEPSS 0.2%CVE-2022-48518Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. SuccEPSS 0.1%CVE-2024-42030MEDIUMAccess permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may EPSS 0.1%CVE-2024-8298MEDIUMMemory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidEPSS 0.1%CVE-2026-41979MEDIUMPermission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect integrity and confideEPSS 0.1%CVE-2026-58557MEDIUMDesign defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-41975MEDIUMPermission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect serviEPSS 0.1%