Fallos del tipo CWE-287

2451 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-42463HIGHSoftbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary co ...EPSS 0.3%CVE-2023-30560MEDIUM PCU Configuration Lacks AuthenticationEPSS 0.3%CVE-2025-21450CRITICALImproper Authentication in GPS_GNSSEPSS 0.3%CVE-2026-44810HIGHMicrosoft Cryptographic Services Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-79974MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper AuthentiEPSS 0.3%CVE-2026-60908HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.3%CVE-2026-82980MEDIUMAny authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves fEPSS 0.3%CVE-2026-22099HIGHMissing authentication for Bluetooth communicationEPSS 0.3%CVE-2026-34389MEDIUMFleet's user account creation via invite does not enforce invited email addressEPSS 0.3%CVE-2026-19273MEDIUMThe Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Improper Access ControlEPSS 0.3%CVE-2025-53545MEDIUMPress has a potential 2FA bypassEPSS 0.3%CVE-2026-61049HIGHVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2026-26141HIGHHybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-57107HIGHWindows Admin Center Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-29062LOWUnsecure Identity VerificationEPSS 0.3%CVE-2024-47174MEDIUMCredential leak when credentials are used with `<nix/fetchurl.nix>`EPSS 0.3%CVE-2026-10283MEDIUMBottelet DaybydayCRM Setting missing authenticationEPSS 0.3%CVE-2023-20012MEDIUMCisco Nexus 9300-FX3 Series Fabric Extender for UCS Fabric Interconnects Authentication Bypass VulnerabilityEPSS 0.3%CVE-2025-29627MEDIUMAn issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric AuthenticatioEPSS 0.3%CVE-2024-40778LOWAn authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadEPSS 0.3%