Weaknesses of type CWE-290

606 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2023-36883MEDIUMMicrosoft Edge for iOS Spoofing VulnerabilityEPSS 0.6%CVE-2023-41329LOWDomain restrictions bypass via DNS Rebinding in WireMock and WireMock StudioEPSS 0.6%CVE-2026-69843CRITICALMicrosoft Fabric Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-42354CRITICALSentry: Improper authentication on SAML SSO process allows user identity linkingEPSS 0.6%CVE-2026-50755CRITICALAn issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header valueEPSS 0.6%CVE-2019-3884LOWA vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from anothEPSS 0.6%CVE-2026-55652CRITICALWekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)EPSS 0.6%CVE-2023-2807MEDIUMAuthentication bypass in password reset processEPSS 0.6%CVE-2023-23398HIGHMicrosoft Excel Spoofing VulnerabilityEPSS 0.6%CVE-2021-27861MEDIUML2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with invalid lengthsEPSS 0.6%CVE-2026-49757CRITICALOAuth2/OIDC account takeover in AshAuthentication via email-based user matchingEPSS 0.6%CVE-2023-28452HIGHAn issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore vEPSS 0.6%CVE-2024-46957CRITICALMellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is EPSS 0.6%CVE-2026-54089CRITICALFile Browser: Authentication Bypass via Proxy Auth Header ForgeryEPSS 0.6%CVE-2026-13207HIGHFrangoteam FUXA SCADA/HMI Authentication Bypass by SpoofingEPSS 0.6%CVE-2025-34053MEDIUMAVTECH IP camera, DVR, and NVR Devices Authentication Bypass via .cab Path ManipulationEPSS 0.6%CVE-2023-3243HIGH ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a pEPSS 0.6%CVE-2025-27671CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Device Impersonation OVE-20230524-0EPSS 0.6%CVE-2022-41798MEDIUMSession information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacenEPSS 0.6%CVE-2024-22520HIGHAn issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets.EPSS 0.6%