VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (904)

page 25 of 46
  • CVE-2024-28919MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-28903MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-26250MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-20669MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2023-25945MedFeb 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Protection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27383MedNov 14, 2023
    risk 0.44cvss 6.8epss 0.00

    Protection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a privileged user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-3453MedJul 16, 2021
    risk 0.44cvss 6.8epss 0.00

    Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.

  • CVE-2020-3458MedOct 21, 2020
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass the…

  • CVE-2020-7320MedSep 9, 2020
    risk 0.44cvss 6.7epss 0.00

    Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft…

  • CVE-2020-5379MedSep 2, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management…

  • CVE-2020-7277MedApr 15, 2020
    risk 0.44cvss 6.8epss 0.00

    Protection mechanism failure in all processes in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows local users to stop certain McAfee ENS processes, reducing the protection offered.

  • CVE-2020-6977MedFeb 20, 2020
    risk 0.44cvss 6.8epss 0.00

    A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include…

  • CVE-2019-19278MedJan 16, 2020
    risk 0.44cvss 6.8epss 0.00

    A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR32..-.....-.... MLFB 6SR4...-.....-.... MLFB 6SR5...-.....-.... With option A30 (HMIs 12 inches or larger) (All versions), SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR325.-.....-.... (High…

  • CVE-2018-9314MedMay 31, 2018
    risk 0.44cvss 6.8epss 0.01

    The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows an attack by an attacker who has direct physical access.

  • CVE-2026-61792HigAug 26, 2026
    risk 0.43cvss 7.7epss 0.01

    Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths…

  • CVE-2026-0017HigMar 2, 2026
    risk 0.43cvss 7.7epss 0.00

    In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-57135HigSep 15, 2026
    risk 0.42cvss 7.6epss 0.00

    PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an…

  • CVE-2026-47424HigSep 15, 2026
    risk 0.42cvss —epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin…

  • CVE-2026-45770HigSep 10, 2026
    risk 0.42cvss 7.5epss 0.00

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua detection state and may bypass Suricata's…

  • CVE-2026-84811MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.01

    agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious __pycache__ entries alongside benign source files. Attackers can execute arbitrary Python bytecode on import…