Weaknesses of type CWE-657

19 results

Violação de Princípios de Design Seguro

É uma categoria ampla que descreve quando um sistema é arquitetado ou implementado de forma que ignora princípios fundamentais de segurança — como separação de responsabilidades, princípio do menor privilégio, ou validação em camadas. O resultado é que a segurança fica frágil e exploração se torna mais fácil, mesmo que bugs individuais pareçam menores.

Example

Uma aplicação que confia inteiramente em validação no frontend, sem duplicar verificações no backend. Ou um serviço que executa operações críticas com permissões elevadas o tempo todo, em vez de elevar privilégios apenas quando necessário. Quando surgem falhas (bypass de validação, injeção), o sistema inteiro cai.

How to mitigate

Revise a arquitetura: implemente validação em múltiplas camadas, aplique separação de privilégios (execute com menor permissão possível), use defesa em profundidade, e documente quais princípios de segurança cada componente respeita. Envolva arquitetos de segurança desde o design, não apenas em code review.

CVE-2023-29320HIGHZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flawEPSS 4.6%CVE-2022-28244MEDIUMAdobe Acrobat Reader DC CSP Bypass Leads To Privilege EscalationEPSS 3.6%CVE-2021-44714LOWAdobe Acrobat Reader Missing Custom Protocols in Warning Message PromptsEPSS 2.5%CVE-2021-28583HIGHMagento Commerce insecure storage of sensitive documentationEPSS 1.9%CVE-2017-6032A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has EPSS 1.7%CVE-2021-36061MEDIUMAdobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting RecordingsEPSS 1.6%CVE-2019-15611Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when searEPSS 1.1%CVE-2020-8133A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.EPSS 0.7%CVE-2022-30683MEDIUMAEM Violation of Secure Design Principles Security feature bypassEPSS 0.6%CVE-2026-39888CRITICALPraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)EPSS 0.5%CVE-2026-48399HIGHAdobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)EPSS 0.5%CVE-2024-26139HIGHOpenCTI Authenticated Privilege EscalationEPSS 0.4%CVE-2024-33849MEDIUMci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.EPSS 0.4%CVE-2019-0061HIGHJunos OS: Insecure management daemon (MGD) configuration may allow local privilege escalationEPSS 0.4%CVE-2023-52714HIGHVulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affEPSS 0.3%CVE-2024-57957MEDIUMVulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affecEPSS 0.3%CVE-2019-5478A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the controlEPSS 0.2%CVE-2025-54255MEDIUMAcrobat Reader | Violation of Secure Design Principles (CWE-657)EPSS 0.2%CVE-2025-24887MEDIUMOpenCTI bypass of protected attribute updateEPSS 0.2%