Fallos del tipo CWE-287

2412 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2021-34865HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. AuthentEPSS 3.1%CVE-2018-14786Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.EPSS 3.1%CVE-2020-3297HIGHCisco Small Business Smart and Managed Switches Session Management VulnerabilityEPSS 3.0%CVE-2021-25036All In One SEO < 4.1.5.3 - Authenticated Privilege EscalationEPSS 3.0%CVE-2025-1104MEDIUMD-Link DHP-W310AV authentication spoofingEPSS 3.0%CVE-2020-8206An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bEPSS 3.0%CVE-2017-14008GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.EPSS 3.0%CVE-2017-6869A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remEPSS 3.0%CVE-2025-30287HIGHColdFusion | Improper Authentication (CWE-287)EPSS 2.9%CVE-2022-24882CRITICALServer side NTLM does not properly check parameters in FreeRDPEPSS 2.8%CVE-2017-11429HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.7%CVE-2020-10918HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch EPSS 2.7%CVE-2023-46290HIGHRockwell Automation FactoryTalk Services Platform Elevated Privileges VulnerabilityEPSS 2.7%CVE-2017-7920An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for ReEPSS 2.7%CVE-2022-40664CRITICALAuthentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcherEPSS 2.7%CVE-2018-13804A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UAEPSS 2.7%CVE-2018-5459An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute dEPSS 2.7%CVE-2018-5451In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficienEPSS 2.6%CVE-2018-0271A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker toEPSS 2.6%CVE-2017-7919An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific EPSS 2.6%