VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (896)

page 21 of 45
  • CVE-2021-1223HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could…

  • CVE-2019-12697HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section…

  • CVE-2019-12696HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.01

    Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section…

  • CVE-2019-3586HigMay 15, 2019
    risk 0.49cvss 7.5epss 0.01

    Protection Mechanism Failure in the Firewall in McAfee Endpoint Security (ENS) 10.x prior to 10.6.1 May 2019 update allows context-dependent attackers to circumvent ENS protection where GTI flagged IP addresses are not blocked by the ENS Firewall via specially crafted malicious…

  • CVE-2019-5024HigApr 11, 2019
    risk 0.49cvss 7.6epss 0.00

    A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical information collection devices running versions 9.0.3 or lower. A specific series of keyboard inputs can escape the restricted environment,…

  • CVE-2019-10906HigApr 7, 2019
    risk 0.49cvss 8.6epss 0.04

    In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

  • CVE-2018-0094HigJan 18, 2018
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted device. The vulnerability is due to insufficient rate…

  • CVE-2026-76825HigSep 16, 2026
    risk 0.48cvss 8.4epss 0.01

    RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the…

  • CVE-2026-79774HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.01

    Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding…

  • CVE-2026-48033HigJul 24, 2026
    risk 0.48cvss —epss 0.00

    Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.

  • CVE-2026-32202MedKEVApr 14, 2026
    risk 0.48cvss 4.3epss 0.05

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-0011HigMar 2, 2026
    risk 0.48cvss 8.4epss 0.00

    In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-59033HigSep 8, 2025
    risk 0.48cvss 7.4epss 0.00

    The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash…

  • CVE-2024-38217MedKEVSep 10, 2024
    risk 0.48cvss 5.4epss 0.10

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2024-45411HigSep 9, 2024
    risk 0.48cvss 8.5epss 0.01

    Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

  • CVE-2023-32493HigAug 16, 2023
    risk 0.48cvss 7.3epss 0.01

    Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution.

  • CVE-2022-39957HigSep 20, 2022
    risk 0.48cvss 7.3epss 0.01

    The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be…

  • CVE-2022-33631HigAug 9, 2022
    risk 0.48cvss 7.3epss 0.01

    Microsoft Excel Security Feature Bypass Vulnerability

  • CVE-2017-2685HigMar 1, 2017
    risk 0.48cvss 7.4epss 0.01

    Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a…

  • CVE-2026-77251HigSep 22, 2026
    risk 0.47cvss —epss 0.00

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence search uses an incomplete case-sensitive…