VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (894)

page 28 of 45
  • CVE-2022-48219MedFeb 14, 2024
    risk 0.42cvss 6.4epss 0.00

    Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.

  • CVE-2024-0747MedJan 23, 2024
    risk 0.42cvss 6.5epss 0.01

    When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

  • CVE-2023-38157MedAug 7, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2023-0131MedJan 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-46698MedDec 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.

  • CVE-2022-3056MedSep 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2022-3044MedSep 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

  • CVE-2022-34175HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.

  • CVE-2021-27497MedApr 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

  • CVE-2022-25186MedFeb 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the agent, allowing attackers able to control agent processes to obtain Vault secrets for an attacker-specified path and key.

  • CVE-2021-31362MedOct 19, 2021
    risk 0.42cvss 6.5epss 0.00

    A Protection Mechanism Failure vulnerability in RPD (routing protocol daemon) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause established IS-IS adjacencies to go down by sending a spoofed hello PDU leading to a Denial of…

  • CVE-2020-15174HigOct 6, 2020
    risk 0.42cvss 7.5epss 0.01

    In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent navigations to unexpected destinations as per our security recommendations can be bypassed when a sub-frame performs a top-frame navigation across sites. The…

  • CVE-2019-10330HigMay 31, 2019
    risk 0.42cvss 7.5epss 0.02

    Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.

  • CVE-2026-17079MedAug 14, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.

  • CVE-2026-10174MedMay 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation of the argument git-commit-verify leads to protection mechanism failure. The attack may be launched…

  • CVE-2025-24848MedNov 11, 2025
    risk 0.41cvss 6.3epss 0.00

    Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable…

  • CVE-2025-60711MedOct 31, 2025
    risk 0.41cvss 6.3epss 0.00

    Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2024-20438MedOct 2, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker…

  • CVE-2023-42918MedJul 29, 2024
    risk 0.41cvss 6.3epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2022-36085HigSep 8, 2022
    risk 0.41cvss 7.4epss 0.02

    Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a set of built-in functions that should be deemed unsafe — and as such rejected — by the compiler…