Weaknesses of type CWE-290

606 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2024-49193HIGHZendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming EPSS 0.7%CVE-2023-22814CRITICALAuthentication Bypass issue in My Cloud OS 5 devicesEPSS 0.7%CVE-2022-40269MEDIUMAuthentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.14.000 to 01.47.000EPSS 0.7%CVE-2024-1547MEDIUMThrough a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victEPSS 0.7%CVE-2024-31008MEDIUMAn issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the indEPSS 0.7%CVE-2024-39350HIGHA vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to oEPSS 0.7%CVE-2024-53862MEDIUMArgo Workflows Allows Access to Archived Workflows with Fake Token in `client` modeEPSS 0.7%CVE-2021-27862MEDIUML2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with an invalid length during Ethernet to Wifi frame translationEPSS 0.7%CVE-2023-22474HIGHParse Server is vulnerable to authentication bypass via spoofingEPSS 0.7%CVE-2026-22797CRITICALAn issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1EPSS 0.7%CVE-2018-25318CRITICALTenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS ChangeEPSS 0.7%CVE-2018-25316CRITICALTenda W308R v2 V5.07.48 Cookie Session Weakness DNS ChangeEPSS 0.7%CVE-2018-25317CRITICALTenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS ChangeEPSS 0.7%CVE-2024-3843MEDIUMInsufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a craEPSS 0.6%CVE-2023-38173MEDIUMMicrosoft Edge for Android Spoofing VulnerabilityEPSS 0.6%CVE-2023-41133MEDIUMWordPress Secure Admin IP plugin <= 2.0 - IP Spoofing vulnerabilityEPSS 0.6%CVE-2025-59385HIGHQTS, QuTS heroEPSS 0.6%CVE-2026-39999HIGHApache APISIX: JWT Algorithm Confusion allows authentication bypassEPSS 0.6%CVE-2026-24013CRITICALApache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPCEPSS 0.6%CVE-2024-22519HIGHAn issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets.EPSS 0.6%