Fallos del tipo CWE-696

40 resultados

Ordem incorreta de operações de segurança

A aplicação executa operações críticas de segurança em sequência errada, permitindo que um estado intermediário seja explorado antes de validações ou proteções serem aplicadas. Por exemplo: conceder acesso antes de completar autenticação, ou usar dados antes de sanitizá-los.

Ejemplo

Um sistema que carrega dados do usuário em memória, aplica lógica de negócio, e só depois valida permissões. Um atacante pode manipular o fluxo para processar operações sensíveis antes da validação de autorização ocorrer, contornando controles de acesso.

Cómo mitigar

Sempre execute validações (autenticação, autorização, sanitização) antes de qualquer operação sensível. Arquitete o fluxo com camadas de defesa ordenadas: verificar credenciais → validar permissões → sanitizar entrada → processar dados. Use testes de segurança para confirmar a sequência.

CVE-2024-30410MEDIUMJunos OS: EX4300 Series: Loopback filter not blocking traffic despite having discard term.EPSS 0.4%CVE-2024-30389MEDIUMJunos OS: EX4300 Series: Firewall filter not blocking egress trafficEPSS 0.4%CVE-2025-55114MEDIUMBMC Control-M/Agent improper IP address filtering orderEPSS 0.4%CVE-2025-9904MEDIUMUnallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / GenerEPSS 0.4%CVE-2026-45033HIGHGitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorEPSS 0.4%CVE-2026-35386LOWIn OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario wEPSS 0.3%CVE-2026-14169HIGHads-tec Industrial IT: Account lockout via non-atomic user creationEPSS 0.3%CVE-2023-23576MEDIUM Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than inteEPSS 0.3%CVE-2026-35636HIGHOpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId ResolutionEPSS 0.3%CVE-2026-67217MEDIUMcJSON JSON Patch Non-Atomic Application Destroys Data Before ValidationEPSS 0.3%CVE-2026-35637MEDIUMOpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DMEPSS 0.2%CVE-2024-45157MEDIUMAn issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously EPSS 0.2%CVE-2024-24853HIGHIncorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a priviEPSS 0.2%CVE-2025-20012MEDIUMIncorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable information discloEPSS 0.2%CVE-2026-68930MEDIUMRussh: Channel-scoped server callbacks can be reached without an open channelEPSS 0.2%CVE-2026-33305MEDIUMOpenEMR has Authorization Bypass in FaxSMS AppDispatch ConstructorEPSS 0.2%CVE-2021-47688MEDIUMIn WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file cEPSS 0.2%CVE-2026-49317LOWIndian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at bootEPSS 0.1%CVE-2026-49318LOWIndian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at bootEPSS 0.1%CVE-2026-40223MEDIUMIn systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.EPSS 0.1%