PillarDraft

CWE-693Protection Mechanism Failure

Category: other

Description

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.

Common consequences· 1

  • Access Control — Bypass Protection Mechanism

Related CAPEC attack patterns· 17

CAPEC-1CAPEC-107CAPEC-127CAPEC-17CAPEC-20CAPEC-22CAPEC-237CAPEC-36CAPEC-477CAPEC-480CAPEC-51CAPEC-57CAPEC-59CAPEC-65CAPEC-668CAPEC-74CAPEC-87

References

  1. https://cwe.mitre.org/data/definitions/693.html

Exploits (incoming)17

TypeTargetConfidenceTier
AttackPatternSignature Spoofing by Mixing Signed and Unsigned Contentcapec-477100%live
AttackPatternExploiting Trust in Clientcapec-22100%live
AttackPatternSniff Application Codecapec-65100%live
AttackPatternPoison Web Service Registrycapec-51100%live
AttackPatternEncryption Brute Forcingcapec-20100%live
AttackPatternUsing Malicious Filescapec-17100%live
AttackPatternDirectory Indexingcapec-127100%live
AttackPatternSession Credential Falsification through Predictioncapec-59100%live
AttackPatternManipulating Statecapec-74100%live
AttackPatternAccessing Functionality Not Properly Constrained by ACLscapec-1100%live
AttackPatternEscaping a Sandbox by Calling Code in Another Languagecapec-237100%live
AttackPatternUtilizing REST's Trust in the System Resource to Obtain Sensitive Datacapec-57100%live
AttackPatternUsing Unpublished Interfaces or Functionalitycapec-36100%live
AttackPatternCross Site Tracingcapec-107100%live
AttackPatternEscaping Virtualizationcapec-480100%live
AttackPatternForceful Browsingcapec-87100%live
AttackPatternKey Negotiation of Bluetooth Attack (KNOB)capec-668100%live

Compliance frameworks addressing this (incoming)6

TypeTargetConfidenceTier
ComplianceControlowasp_top10-a04100%live
ComplianceControldora-art24100%live
ComplianceControldora-art9100%live
ComplianceControlpci_dss_v4-r1100%live
ComplianceControldora-art8100%live
ComplianceControlnist_csf-id100%live

(incoming)89

TypeTargetConfidenceTier
Vulnerability7-Zip Mark of the Web Bypass Vulnerabilitycve-2025-04110%live
VulnerabilityCVE-2025-12554cve-2025-125540%live
VulnerabilityCVE-2025-15618cve-2025-156180%live
VulnerabilityCVE-2025-21384cve-2025-213840%live
VulnerabilityCVE-2025-22429cve-2025-224290%live
VulnerabilityCVE-2025-27665cve-2025-276650%live
VulnerabilityCVE-2025-27700cve-2025-277000%live
VulnerabilityCVE-2025-31189cve-2025-311890%live
VulnerabilityCVE-2025-31244cve-2025-312440%live
VulnerabilityCVE-2025-37124cve-2025-371240%live
VulnerabilitySolarWinds Web Help Desk Security Control Bypass Vulnerabilitycve-2025-405360%live
VulnerabilityCVE-2025-41224cve-2025-412240%live
VulnerabilityCVE-2025-41232cve-2025-412320%live
VulnerabilityCVE-2025-43261cve-2025-432610%live
VulnerabilityCVE-2025-43273cve-2025-432730%live
VulnerabilityCVE-2025-43330cve-2025-433300%live
VulnerabilityCVE-2025-43728cve-2025-437280%live
VulnerabilityCVE-2025-46281cve-2025-462810%live
VulnerabilityCVE-2025-48534cve-2025-485340%live
VulnerabilityCVE-2025-48602cve-2025-486020%live
VulnerabilityCVE-2025-48605cve-2025-486050%live
VulnerabilityCVE-2025-48626cve-2025-486260%live
VulnerabilityCVE-2025-49740cve-2025-497400%live
VulnerabilityCVE-2025-54143cve-2025-541430%live
VulnerabilityCVE-2025-6427cve-2025-64270%live
VulnerabilityCVE-2025-65318cve-2025-653180%live
VulnerabilityCVE-2025-65319cve-2025-653190%live
VulnerabilityCVE-2025-66204cve-2025-662040%live
VulnerabilityCVE-2025-68668cve-2025-686680%live
VulnerabilityCVE-2025-69264cve-2025-692640%live

Showing top 30 of 89 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Incorrect Implementation of Authentication Algorithm
CWE
Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')
CWE
Improperly Implemented Security Check for Standard
CWE
Violation of Secure Design Principles
CWE
Inadequate Encryption Strength
CWE
Improper Access Control
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.