Weaknesses of type CWE-287

2,431 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2021-26637HIGHSiHAS Improper Authentication vulnerabilityEPSS 1.9%CVE-2021-32637CRITICALAuthentication bypassed with malformed request URIEPSS 1.9%CVE-2017-14004—GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful explEPSS 1.9%CVE-2017-14006—GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-codedEPSS 1.9%CVE-2021-21308MEDIUMImproper session management for soft logoutEPSS 1.9%CVE-2017-12695—An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitationEPSS 1.9%CVE-2017-6047—Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessible without authenticEPSS 1.8%CVE-2018-0087—A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to theEPSS 1.8%CVE-2018-15721—The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote atEPSS 1.8%CVE-2026-27960CRITICALOpenCTI privilege escalation and unauthenticated access via default admin accountEPSS 1.8%CVE-2018-4836—A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleCEPSS 1.8%CVE-2025-30282CRITICALColdFusion | Improper Authentication (CWE-287)EPSS 1.8%CVE-2021-43999—Improper validation of SAML responsesEPSS 1.8%CVE-2019-1662HIGHCisco Prime Collaboration Assurance Software Unauthenticated Access VulnerabilityEPSS 1.8%CVE-2016-2124—A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent oEPSS 1.8%CVE-2020-4074HIGHImproper AuthenticationEPSS 1.8%CVE-2017-14026—In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allEPSS 1.8%CVE-2021-41157MEDIUMFreeSWITCH does not authenticate SIP SUBSCRIBE requests by defaultEPSS 1.7%CVE-2021-21538CRITICALDell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthentEPSS 1.7%CVE-2021-31349CRITICALSession Smart Router: Authentication Bypass VulnerabilityEPSS 1.7%