Fallos del tipo CWE-1390

95 resultados

Autenticação fraca

A aplicação implementa mecanismos de autenticação insuficientes ou contornáveis, permitindo que um atacante se passe por outro usuário sem credenciais válidas ou com credenciais triviais. Isso ocorre quando o sistema não valida adequadamente a identidade do usuário ou aceita métodos de autenticação inadequados (senhas fracas, sem MFA, tokens previsíveis, etc.).

Ejemplo

Uma API que verifica login apenas checando se um parâmetro 'admin=true' está presente na requisição, ou uma aplicação que aceita qualquer senha com um dígito como válida, permitindo que invasores acessem contas sem credenciais verdadeiras.

Cómo mitigar

Implemente autenticação forte: enforce senhas complexas, use frameworks estabelecidos (OAuth 2.0, SAML), ative multi-factor authentication (MFA), valide credenciais no servidor (nunca no cliente) e use protocolos criptografados. Revise regularmente os mecanismos de autenticação em testes de segurança.

CVE-2024-47397HIGHWeak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vEPSS 0.4%CVE-2025-30468MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessEPSS 0.4%CVE-2024-29038MEDIUMtpm2 does not detect if quote was not generated by TPMEPSS 0.4%CVE-2025-1293HIGHHashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication BypassEPSS 0.3%CVE-2025-47479MEDIUMWordPress WP Compress plugin <= 6.30.30 - Broken Authentication VulnerabilityEPSS 0.3%CVE-2026-4924HIGHImproper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attackeEPSS 0.3%CVE-2024-32119MEDIUMAn improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacEPSS 0.3%CVE-2026-44476MEDIUMDoorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secretEPSS 0.3%CVE-2026-59135MEDIUMMicrosoft Windows Search Component Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-1693MEDIUMUse of vulnerable Resource Owner Password Credentials flowEPSS 0.3%CVE-2026-68067CRITICALMira Hormone Monitor, Mira Android App Weak AuthenticationEPSS 0.3%CVE-2025-0605MEDIUMWeak Authentication in GitLabEPSS 0.3%CVE-2026-0274HIGHCortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integrationEPSS 0.3%CVE-2025-70994HIGHYadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The systeEPSS 0.3%CVE-2026-40417HIGHMicrosoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-57352MEDIUMWordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2026-4828HIGHImproper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid creEPSS 0.3%CVE-2024-5891MEDIUMQuay: unauthorized user may authenticate via oauth application tokenEPSS 0.2%CVE-2025-32885MEDIUMAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom messaEPSS 0.2%CVE-2026-32497MEDIUMWordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerabilityEPSS 0.2%