VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (772)

page 23 of 39
  • CVE-2025-24835MedAug 12, 2025
    risk 0.42cvss 6.5epss 0.00

    Protection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-21217MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.02

    Windows NTLM Spoofing Vulnerability

  • CVE-2024-43513MedOct 8, 2024
    risk 0.42cvss 6.4epss 0.01

    BitLocker Security Feature Bypass Vulnerability

  • CVE-2024-46976MedSep 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or…

  • CVE-2024-43487MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2024-24983MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Protection mechanism failure in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2024-23499MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2023-39368MedMar 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2024-23284MedMar 8, 2024
    risk 0.42cvss 6.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content…

  • CVE-2024-1671MedFeb 21, 2024
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-48219MedFeb 14, 2024
    risk 0.42cvss 6.4epss 0.00

    Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.

  • CVE-2024-0747MedJan 23, 2024
    risk 0.42cvss 6.5epss 0.01

    When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

  • CVE-2023-38157MedAug 7, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2023-0131MedJan 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-46698MedDec 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.

  • CVE-2022-3056MedSep 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2022-3044MedSep 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

  • CVE-2022-34175HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.

  • CVE-2021-27497MedApr 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

  • CVE-2022-25186MedFeb 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.