VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (772)

page 20 of 39
  • CVE-2025-10155HigSep 17, 2025
    risk 0.44cvss 7.8epss 0.01

    An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the…

  • CVE-2025-8656MedAug 6, 2025
    risk 0.44cvss 6.8epss 0.00

    Kenwood DMX958XR Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows physically present attackers to downgrade software on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability. The…

  • CVE-2025-48800MedJul 8, 2025
    risk 0.44cvss 6.8epss 0.01

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-48003MedJul 8, 2025
    risk 0.44cvss 6.8epss 0.01

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-26637MedApr 8, 2025
    risk 0.44cvss 6.8epss 0.01

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-21211MedJan 14, 2025
    risk 0.44cvss 6.8epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-56326HigDec 23, 2024
    risk 0.44cvss 7.8epss 0.01

    Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs…

  • CVE-2024-43645MedNov 12, 2024
    risk 0.44cvss 6.7epss 0.01

    Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability

  • CVE-2024-38058MedJul 9, 2024
    risk 0.44cvss 6.8epss 0.01

    BitLocker Security Feature Bypass Vulnerability

  • CVE-2024-28921MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-28919MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-28903MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-26250MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-20669MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2023-25945MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Protection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27383MedNov 14, 2023
    risk 0.44cvss 6.8epss 0.00

    Protection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a privileged user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-3453MedJul 16, 2021
    risk 0.44cvss 6.8epss 0.00

    Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

  • CVE-2020-3458MedOct 21, 2020
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass the…

  • CVE-2020-7320MedSep 9, 2020
    risk 0.44cvss 6.7epss 0.00

    Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft…

  • CVE-2020-5379MedSep 2, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management…