VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (894)

page 32 of 45
  • CVE-2026-28914MedMay 11, 2026
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

  • CVE-2026-35363MedApr 22, 2026
    risk 0.36cvss 5.6epss 0.00

    A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the utility correctly refuses to delete . or .., it fails to recognize equivalent paths with trailing slashes, such as ./ or .///. An…

  • CVE-2026-20824MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-43296MedOct 9, 2025
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

  • CVE-2025-22431MedSep 2, 2025
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This could lead to local denial of service until the phone reboots with no additional execution privileges…

  • CVE-2024-43585MedOct 8, 2024
    risk 0.36cvss 5.5epss 0.00

    Code Integrity Guard Security Feature Bypass Vulnerability

  • CVE-2024-30050MedMay 14, 2024
    risk 0.36cvss 5.4epss 0.11

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2023-0002MedFeb 8, 2023
    risk 0.36cvss 5.5epss 0.00

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent.

  • CVE-2021-26355MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.

  • CVE-2022-42821MedDec 15, 2022
    risk 0.36cvss 5.5epss 0.04

    A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

  • CVE-2022-20464MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2020-12954MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.

  • CVE-2020-15215MedOct 6, 2020
    risk 0.36cvss 5.6epss 0.01

    Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nodeIntegrationInSubFrames: true` are affected. This is a…

  • CVE-2026-57120MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level attribute access that bypasses _safe_getattr.…

  • CVE-2026-84809MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source…

  • CVE-2026-62902MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.01

    Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-28757MedAug 11, 2026
    risk 0.35cvss —epss 0.00

    Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of…

  • CVE-2026-28707MedAug 11, 2026
    risk 0.35cvss —epss 0.00

    Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result…

  • CVE-2026-24693MedAug 11, 2026
    risk 0.35cvss —epss 0.00

    Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable…

  • CVE-2026-21400MedAug 11, 2026
    risk 0.35cvss —epss 0.00

    Protection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of…