Fallos del tipo CWE-1390

95 resultados

Autenticação fraca

A aplicação implementa mecanismos de autenticação insuficientes ou contornáveis, permitindo que um atacante se passe por outro usuário sem credenciais válidas ou com credenciais triviais. Isso ocorre quando o sistema não valida adequadamente a identidade do usuário ou aceita métodos de autenticação inadequados (senhas fracas, sem MFA, tokens previsíveis, etc.).

Ejemplo

Uma API que verifica login apenas checando se um parâmetro 'admin=true' está presente na requisição, ou uma aplicação que aceita qualquer senha com um dígito como válida, permitindo que invasores acessem contas sem credenciais verdadeiras.

Cómo mitigar

Implemente autenticação forte: enforce senhas complexas, use frameworks estabelecidos (OAuth 2.0, SAML), ative multi-factor authentication (MFA), valide credenciais no servidor (nunca no cliente) e use protocolos criptografados. Revise regularmente os mecanismos de autenticação em testes de segurança.

CVE-2025-57713LOWFile Station 5EPSS 0.5%CVE-2026-73819CRITICALEbyte NA111-M Weak AuthenticationEPSS 0.5%CVE-2026-77483HIGHSQL Server Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2024-29837HIGHPoor session management in Evolution Controller allows administrator functionality for unauthenticated connectionsEPSS 0.5%CVE-2024-45367CRITICALOptigo Networks ONS-S8 Spectra Aggregation Switch Weak AuthenticationEPSS 0.5%CVE-2026-50756HIGHAn issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider componentEPSS 0.5%CVE-2025-50173HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-4094MEDIUMWeak authentication vulnerability in Fujitsu Arconte ÁureaEPSS 0.5%CVE-2025-63807CRITICALAn issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak EPSS 0.5%CVE-2022-45860MEDIUMA weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versEPSS 0.5%CVE-2024-48886HIGHA weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, ForEPSS 0.5%CVE-2026-6274CRITICALAuthentication Bypass in DTS Electronics' Redline WR3200EPSS 0.5%CVE-2025-5484HIGHSinoTrack GPS Receiver Weak AuthenticationEPSS 0.5%CVE-2026-6886CRITICALBorG Technology Corporation|Borg SPM 2007 - Authentication BypassEPSS 0.5%CVE-2024-39848CRITICALInternet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.midEPSS 0.4%CVE-2026-59554HIGHWordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerabilityEPSS 0.4%CVE-2026-0204HIGHA vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific EPSS 0.4%CVE-2025-21552MEDIUMVulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). SupporteEPSS 0.4%CVE-2026-28710HIGHSensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber ProtectEPSS 0.4%CVE-2025-29994HIGHImproper Authentication Vulnerability in CAP back office applicationEPSS 0.4%