VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (772)

page 17 of 39
  • CVE-2023-34984HigSep 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

  • CVE-2023-35352HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Windows Remote Desktop Security Feature Bypass Vulnerability

  • CVE-2022-48287HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2022-46762HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-32910HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Security Update 2022-005 Catalina. An archive may be able to bypass Gatekeeper.

  • CVE-2022-43429HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.

  • CVE-2022-39011HigOct 14, 2022
    risk 0.49cvss 7.5epss 0.00

    The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.

  • CVE-2021-1223HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could…

  • CVE-2019-12697HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section…

  • CVE-2019-12696HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section…

  • CVE-2019-3586HigMay 15, 2019
    risk 0.49cvss 7.5epss 0.01

    Protection Mechanism Failure in the Firewall in McAfee Endpoint Security (ENS) 10.x prior to 10.6.1 May 2019 update allows context-dependent attackers to circumvent ENS protection where GTI flagged IP addresses are not blocked by the ENS Firewall via specially crafted malicious…

  • CVE-2019-5024HigApr 11, 2019
    risk 0.49cvss 7.6epss 0.00

    A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical information collection devices running versions 9.0.3 or lower. A specific series of keyboard inputs can escape the restricted environment,…

  • CVE-2019-10906HigApr 7, 2019
    risk 0.49cvss 8.6epss 0.04

    In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

  • CVE-2018-0094HigJan 18, 2018
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted device. The vulnerability is due to insufficient rate…

  • CVE-2026-48033HigJul 24, 2026
    risk 0.48cvss epss 0.00

    Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.

  • CVE-2026-32202MedKEVApr 14, 2026
    risk 0.48cvss 4.3epss 0.64

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-59033HigSep 8, 2025
    risk 0.48cvss 7.4epss 0.00

    The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash…

  • CVE-2024-38217MedKEVSep 10, 2024
    risk 0.48cvss 5.4epss 0.10

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2024-45411HigSep 9, 2024
    risk 0.48cvss 8.5epss 0.01

    Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

  • CVE-2023-32493HigAug 16, 2023
    risk 0.48cvss 7.3epss 0.01

    Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution.