Falhas do tipo CWE-691

33 resultados

Controle de Fluxo Insuficiente

É quando o código não valida ou não controla adequadamente quais caminhos de execução podem ser seguidos, permitindo que o programa execute instruções indesejadas ou pule validações críticas. Acontece quando faltam verificações de precondições, estado da aplicação ou permissões antes de executar operações sensíveis.

Exemplo

Um sistema de autenticação que verifica a senha, mas não valida se o usuário ainda está ativo ou se sua sessão expirou antes de conceder acesso a dados sensíveis. Ou um aplicativo que executa uma transação financeira sem confirmar se o estado da conta permite tal operação.

Como mitigar

Implemente validações explícitas de estado e permissões em todos os pontos críticos do código; use máquinas de estado para operações sensíveis e realize testes de caminhos de execução alternativos para detectar saltos indevidos no fluxo esperado.

CVE-2023-24587MEDIUMInsufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enableEPSS 0.2%CVE-2025-35963HIGHInsufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: DeviceEPSS 0.2%CVE-2024-25565MEDIUMInsufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial EPSS 0.2%CVE-2022-37409MEDIUMInsufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potEPSS 0.2%CVE-2022-41646MEDIUMInsufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to poEPSS 0.2%CVE-2023-28711MEDIUMInsufficient control flow management in the Hyperscan Library maintained by Intel(R) before version 5.4.1 may allow an authenticated user toEPSS 0.2%CVE-2024-22374MEDIUMInsufficient control flow management for some Intel(R) Xeon Processors may allow an authenticated user to potentially enable denial of serviEPSS 0.2%CVE-2022-43505MEDIUMInsufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denEPSS 0.2%CVE-2025-24305HIGHInsufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) processors may allow a pEPSS 0.1%CVE-2025-20004HIGHInsufficient control flow management in the Alias Checking Trusted Module for some Intel(R) Xeon(R) 6 processor E-Cores firmware may allow aEPSS 0.1%CVE-2025-25273HIGHInsufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow aEPSS 0.1%CVE-2025-22893HIGHInsufficient control flow management in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow aEPSS 0.1%CVE-2026-5938MEDIUMFoxit PDF Editor/Reader Infinite Loop Denial-of-Service VulnerabilityEPSS 0.1%