VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (902)

page 24 of 46
  • CVE-2026-50646HigJul 14, 2026
    risk 0.44cvss 7.8epss 0.04

    Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

  • CVE-2026-1232MedFeb 2, 2026
    risk 0.44cvss —epss 0.00

    A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Under certain conditions, a local authenticated user with elevated privileges may be able to bypass the product’s anti-tamper protections, which could allow…

  • CVE-2025-14095MedDec 17, 2025
    risk 0.44cvss 6.8epss 0.00

    A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user with physical access to the analyzer, the possibility to gain unauthorized access to functionalities outside the restricted…

  • CVE-2025-14304MedDec 17, 2025
    risk 0.44cvss 6.8epss 0.00

    Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write…

  • CVE-2025-14303MedDec 17, 2025
    risk 0.44cvss 6.8epss 0.00

    Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its…

  • CVE-2025-14302MedDec 17, 2025
    risk 0.44cvss 6.8epss 0.00

    Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and…

  • CVE-2025-36938MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.00

    In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-10157HigSep 17, 2025
    risk 0.44cvss 7.8epss 0.01

    A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possible because the scanner performs an exact match for module names, allowing malicious payloads to be…

  • CVE-2025-10155HigSep 17, 2025
    risk 0.44cvss 7.8epss 0.01

    An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the…

  • CVE-2025-8656MedAug 6, 2025
    risk 0.44cvss 6.8epss 0.00

    Kenwood DMX958XR Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows physically present attackers to downgrade software on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability. The…

  • CVE-2025-48800MedJul 8, 2025
    risk 0.44cvss 6.8epss 0.01

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-48003MedJul 8, 2025
    risk 0.44cvss 6.8epss 0.01

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-26637MedApr 8, 2025
    risk 0.44cvss 6.8epss 0.01

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-21211MedJan 14, 2025
    risk 0.44cvss 6.8epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-56326HigDec 23, 2024
    risk 0.44cvss 7.8epss 0.01

    Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs…

  • CVE-2024-43645MedNov 12, 2024
    risk 0.44cvss 6.7epss 0.01

    Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability

  • CVE-2024-38058MedJul 9, 2024
    risk 0.44cvss 6.8epss 0.01

    BitLocker Security Feature Bypass Vulnerability

  • CVE-2024-28921MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-28919MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-28903MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability