VYPR

CWE-693

Protection Mechanism Failure

PillarDraft

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87

CVEs mapped to this weakness (771)

page 8 of 39
  • CVE-2025-9866HigSep 3, 2025
    risk 0.57cvss 8.8epss 0.00

    Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-49740HigJul 8, 2025
    risk 0.57cvss 8.8epss 0.01

    Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-41224HigJul 8, 2025
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.10.0), RUGGEDCOM RS416NCv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416PNCv2 V5.X (All versions < V5.10.0), RUGGEDCOM RS416Pv2 V5.X (All versions…

  • CVE-2025-31244HigMay 12, 2025
    risk 0.57cvss 8.8epss 0.00

    A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.

  • CVE-2024-36242HigNov 13, 2024
    risk 0.57cvss 8.8epss 0.00

    Protection mechanism failure in the SPP for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-44122HigOct 28, 2024
    risk 0.57cvss 8.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An application may be able to break out of its sandbox.

  • CVE-2024-38180HigAug 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows SmartScreen Security Feature Bypass Vulnerability

  • CVE-2024-38092HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Azure CycleCloud Elevation of Privilege Vulnerability

  • CVE-2024-27713HigJul 5, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings component.

  • CVE-2024-5924HigJun 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the…

  • CVE-2023-51748HigJan 11, 2024
    risk 0.57cvss 8.8epss 0.00

    ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

  • CVE-2023-32006HigAug 15, 2023
    risk 0.57cvss 8.8epss 0.02

    The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x,…

  • CVE-2021-31982HigJul 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2023-25765CriFeb 15, 2023
    risk 0.57cvss 9.9epss 0.01

    In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the…

  • CVE-2022-22761HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.01

    Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

  • CVE-2022-33942HigNov 11, 2022
    risk 0.57cvss 8.8epss 0.01

    Protection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-26696HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.00

    This issue was addressed with improved environment sanitization. This issue is fixed in macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2022-23118HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.02

    Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.

  • CVE-2021-21696CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.02

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not limit agent read/write access to the libs/ directory inside build directories when using the FilePath APIs, allowing attackers in control of agent processes to replace the code of a trusted library with a modified…

  • CVE-2021-21690CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.02

    Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.