VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (894)

page 27 of 45
  • CVE-2026-5903MedApr 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-5276MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-20665MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.01

    This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content…

  • CVE-2026-24868MedJan 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.

  • CVE-2025-35968MedNov 11, 2025
    risk 0.42cvss 6.4epss 0.00

    Protection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may…

  • CVE-2025-26402MedNov 11, 2025
    risk 0.42cvss 6.5epss 0.00

    Protection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially…

  • CVE-2025-24834MedNov 11, 2025
    risk 0.42cvss 6.5epss 0.00

    Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data…

  • CVE-2025-0277MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

  • CVE-2025-0276MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

  • CVE-2025-55886MedSep 22, 2025
    risk 0.42cvss 6.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without…

  • CVE-2025-24835MedAug 12, 2025
    risk 0.42cvss 6.5epss 0.00

    Protection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-21217MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.02

    Windows NTLM Spoofing Vulnerability

  • CVE-2024-43513MedOct 8, 2024
    risk 0.42cvss 6.4epss 0.01

    BitLocker Security Feature Bypass Vulnerability

  • CVE-2024-46976MedSep 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or…

  • CVE-2024-43487MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2024-24983MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Protection mechanism failure in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2024-23499MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2023-39368MedMar 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2024-23284MedMar 8, 2024
    risk 0.42cvss 6.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content…

  • CVE-2024-1671MedFeb 21, 2024
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)