Weaknesses of type CWE-287

2,432 results

Falha na autenticação ou verificação insuficiente de identidade

Quando um usuário, sistema ou aplicação afirma ser alguém (ou algo), o software não valida adequadamente essa identidade antes de conceder acesso ou executar ações sensíveis. O risco é claro: um atacante se passa por outra pessoa e obtém privilégios ou dados que não deveria ter.

Example

Um app que aceita um token JWT sem verificar a assinatura, confiando apenas no nome de usuário no payload. Um atacante modifica o token para elevar seu nível de acesso e o sistema acredita, pois nunca validou a autenticidade real do token.

How to mitigate

Implemente autenticação robusta: valide credenciais em backend seguro, use protocolos padrão (OAuth 2.0, SAML, Kerberos), verifique integridade de tokens (assinatura criptográfica), implemente MFA para operações críticas e nunca confie em dados do cliente sem validação no servidor.

CVE-2017-9630—An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, EPSS 1.2%CVE-2019-18322—A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.2%CVE-2019-18321—A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.2%CVE-2024-38124CRITICALWindows Netlogon Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2024-40794MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6.EPSS 1.2%CVE-2023-52160MEDIUMThe implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be confEPSS 1.2%CVE-2025-49831CRITICALConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenticator Bypass via Mis-configured Network DeviceEPSS 1.2%CVE-2022-39219HIGHBifrost users using basic authntication can bypass write permission limitEPSS 1.2%CVE-2020-15164CRITICALAuthentication Bypass in Scratch Login (mediawiki-scratch-login)EPSS 1.2%CVE-2024-23470CRITICALSolarWinds Access Rights Manager (ARM) UserScriptHumster Exposed Dangerous Method Remote Command Execution VulnerabilityEPSS 1.2%CVE-2022-24857HIGHMulti factor authentication bypass in django-mfa3EPSS 1.2%CVE-2022-38744HIGHFactoryTalk Alarm and Events Server Vulnerable to Denial-Of-Service AttackEPSS 1.2%CVE-2018-25043MEDIUMuTorrent PRNG improper authenticationEPSS 1.2%CVE-2025-21349MEDIUMWindows Remote Desktop Configuration Service Tampering VulnerabilityEPSS 1.1%CVE-2022-34839MEDIUMWordPress WP OAuth2 Server plugin <= 1.0.1 - Authentication Bypass vulnerabilityEPSS 1.1%CVE-2025-30430CRITICALThis issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.EPSS 1.1%CVE-2024-51767HIGHAn authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.EPSS 1.1%CVE-2020-3410HIGHCisco Firepower Management Center Software Common Access Card Authentication Bypass VulnerabilityEPSS 1.1%CVE-2021-3632—A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already rEPSS 1.1%CVE-2023-6342MEDIUMTyler Technologies Court Case Management Plus "pay for print" allows authentication bypassEPSS 1.1%