VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (894)

page 29 of 45
  • CVE-2018-10631MedJul 13, 2018
    risk 0.41cvss 6.3epss 0.00

    The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to…

  • CVE-2026-70608HigAug 5, 2026
    risk 0.40cvss 7.2epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenHandler with no user…

  • CVE-2026-44982HigJul 16, 2026
    risk 0.40cvss 7.2epss 0.00

    CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRequestFromRequest allocated a request body buffer from max(r.ContentLength, 0), so HTTP/1.1 requests using Transfer-Encoding: chunked and HTTP/2 requests…

  • CVE-2026-48546HigJun 11, 2026
    risk 0.40cvss 7.3epss 0.00

    KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow.…

  • CVE-2026-5896MedApr 8, 2026
    risk 0.40cvss 6.1epss 0.00

    Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-0012MedMar 2, 2026
    risk 0.40cvss 6.2epss 0.00

    In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-29864MedDec 3, 2025
    risk 0.40cvss —epss 0.00

    Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 before 12.29.

  • CVE-2025-48554MedSep 4, 2025
    risk 0.40cvss 6.1epss 0.00

    In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-38203MedNov 12, 2024
    risk 0.40cvss 6.2epss 0.01

    Windows Package Library Manager Information Disclosure Vulnerability

  • CVE-2024-24980MedAug 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-20665MedApr 9, 2024
    risk 0.40cvss 6.1epss 0.01

    BitLocker Security Feature Bypass Vulnerability

  • CVE-2024-28248HigMar 18, 2024
    risk 0.40cvss 7.2epss 0.01

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 and prior to versions 1.13.13, 1.14.8, and 1.15.2, Cilium's HTTP policies are not consistently applied to all traffic in the scope of the policies, leading to…

  • CVE-2023-22655MedMar 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-30757MedJun 13, 2023
    risk 0.40cvss 6.2epss 0.00

    A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated…

  • CVE-2023-28286MedApr 27, 2023
    risk 0.40cvss 6.1epss 0.01

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2020-10598MedApr 1, 2020
    risk 0.40cvss 6.1epss 0.00

    In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted…

  • CVE-2019-1975MedSep 18, 2019
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could…

  • CVE-2018-0326MedMay 17, 2018
    risk 0.40cvss 6.1epss 0.02

    A vulnerability in the web UI of Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against a user of the web UI of the affected software. The vulnerability is due to insufficient protections for…

  • CVE-2018-7504MedMar 14, 2018
    risk 0.40cvss 6.1epss 0.01

    A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The X-XSS-Protection response header is not set to block, allowing attempts at reflected cross-site scripting.

  • CVE-2026-92959HigSep 17, 2026
    risk 0.39cvss 7.1epss 0.00

    vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve, Promise.all, Promise.race, Promise.any,…