Weaknesses of type CWE-305

168 results

Autenticação tecnicamente correta, mas bypassável por fraqueza secundária

A autenticação em si é implementada corretamente, mas há uma falha em outro ponto do código (validação de entrada, gestão de sessão, controle de acesso) que permite contorná-la sem quebrar o mecanismo de autenticação. É quando o algortimo está certo, mas a orquestração dele falha.

Example

Sistema verifica corretamente senha com hash bcrypt, mas aceita também um parâmetro de URL 'admin=true' que não é validado, permitindo bypass direto dos privilégios de autenticação. Ou: autenticação funciona, mas a geração de tokens de sessão usa sequência previsível ou reutiliza IDs antigos.

How to mitigate

Não confie só na função de autenticação isolada: revise toda a cadeia de autorização (validação de entrada, tratamento de sessão, controle de acesso). Faça teste de penetração focado em bypass, não só em quebra de autenticação; implemente múltiplas camadas de validação e nunca deixe parâmetros de privilégio sob controle do cliente.

CVE-2023-34137SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authenticatioEPSS 1.0%CVE-2022-0451MEDIUMAuth bypass in Dark SDKEPSS 1.0%CVE-2024-7557HIGHOdh-dashboard: odh-model-controller: cross-model authentication bypass in openshift aiEPSS 0.9%CVE-2020-14359A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass oEPSS 0.9%CVE-2025-46801CRITICALPgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerabilEPSS 0.9%CVE-2023-20154CRITICALCisco Modeling Labs External Authentication Bypass VulnerabilityEPSS 0.9%CVE-2024-1202CRITICALAuthentication Bypass in XPodas' OctopodEPSS 0.9%CVE-2024-3847CRITICALInsufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policyEPSS 0.9%CVE-2024-20378HIGHA vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieveEPSS 0.8%CVE-2021-45031HIGHWeak Authentication in Login Function of USC+EPSS 0.8%CVE-2025-24522CRITICALKUNBUS Revolution Pi Authentication Bypass by Primary WeaknessEPSS 0.8%CVE-2023-1833CRITICALAuthentication Bypass in Redline RouterEPSS 0.8%CVE-2023-4501CRITICALAuthentication bypass in OpenText (Micro Focus) Enterprise ServerEPSS 0.8%CVE-2021-28503HIGHIn Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.EPSS 0.7%CVE-2026-86207HIGHAuthentication bypass leads to unauthorised access to N-centralEPSS 0.7%CVE-2026-22153HIGHAn Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauEPSS 0.7%CVE-2023-6153CRITICALAuthentication Bypass in TeoSOFT Software TeoBASEEPSS 0.7%CVE-2025-56132HIGHLiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distiEPSS 0.7%CVE-2023-4898HIGHAuthentication Bypass by Primary Weakness in mintplex-labs/anything-llmEPSS 0.7%CVE-2023-4727HIGHCa: token authentication bypass vulnerabilityEPSS 0.7%