Weaknesses of type CWE-287

2,463 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2024-40653HIGHIn multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a loEPSS 0.1%CVE-2023-2626HIGHAuthentication Bypass in OpenThread Boarder Router devicesEPSS 0.1%CVE-2021-25389LOWImproper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.EPSS 0.1%CVE-2022-25833LOWImproper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permiEPSS 0.1%CVE-2022-25816MEDIUMImproper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable withoEPSS 0.1%CVE-2021-25484MEDIUMImproper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.EPSS 0.1%CVE-2018-11952HIGHImproper Authentication in TrustZoneEPSS 0.1%CVE-2024-42038HIGHVulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect serviceEPSS 0.1%CVE-2022-25817MEDIUMImproper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.EPSS 0.1%CVE-2022-30755HIGHImproper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijaEPSS 0.1%CVE-2026-78236HIGHInsecure PIN derivation mechanism in Admin By Request (ABR)EPSS 0.1%CVE-2016-10394CRITICALImproper Authentication in CoreEPSS 0.1%CVE-2022-33689MEDIUMImproper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unEPSS 0.1%CVE-2026-56792MEDIUMDell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker withEPSS 0.1%CVE-2022-33732MEDIUMImproper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PCEPSS 0.1%CVE-2026-81473HIGHDell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker withEPSS 0.1%CVE-2026-56850MEDIUMA flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to beEPSS 0.1%CVE-2024-29757HIGHthere is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additioEPSS 0.1%CVE-2023-21466MEDIUMPendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access conEPSS 0.1%CVE-2026-94419LOWClient session cache reference poisoning allows resumption with wrong serverEPSS 0.1%