VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (771)

page 27 of 39
  • CVE-2024-30050MedMay 14, 2024
    risk 0.36cvss 5.4epss 0.11

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2023-0002MedFeb 8, 2023
    risk 0.36cvss 5.5epss 0.00

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.

  • CVE-2021-26355MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.

  • CVE-2022-42821MedDec 15, 2022
    risk 0.36cvss 5.5epss 0.04

    A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

  • CVE-2022-20464MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2020-12954MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.

  • CVE-2020-15215MedOct 6, 2020
    risk 0.36cvss 5.6epss 0.01

    Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nodeIntegrationInSubFrames: true` are affected. This is a…

  • CVE-2026-62902MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.01

    Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-28757MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of…

  • CVE-2026-28707MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result…

  • CVE-2026-24693MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable…

  • CVE-2026-21400MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of…

  • CVE-2026-21387MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This…

  • CVE-2026-20906MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation…

  • CVE-2026-20903MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege.…

  • CVE-2026-20770MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable…

  • CVE-2026-20755MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…

  • CVE-2026-20728MedAug 11, 2026
    risk 0.35cvss epss 0.00

    Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable…

  • CVE-2026-17779MedJul 30, 2026
    risk 0.35cvss 5.4epss 0.00

    Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-46639MedJul 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a…