Fallos del tipo CWE-287

2453 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-25452MEDIUMAn issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpointEPSS 0.3%CVE-2026-19842HIGHSAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor OverwriteEPSS 0.3%CVE-2025-11633MEDIUMTomofun Furbo 360/Furbo Mini HTTP Traffic collect_logs.sh upload_file_to_s3 certificate validationEPSS 0.3%CVE-2025-3634MEDIUMMoodle: moodle allows course self-enrolment before completing mfaEPSS 0.3%CVE-2026-17013MEDIUMWP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstartEPSS 0.3%CVE-2024-38822LOWCVE-2024-38822 Salt AdvisoryEPSS 0.3%CVE-2026-73726MEDIUMAuthentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative AccessEPSS 0.3%CVE-2026-19766CRITICALAuthentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric ComposerEPSS 0.3%CVE-2025-2572MEDIUMWhatsUp Gold NmConfigurationManager.exe database manipulation vulnerabilityEPSS 0.3%CVE-2023-43551CRITICALImproper Authentication in Multi-Mode Call ProcessorEPSS 0.3%CVE-2024-13309MEDIUMLogin Disable - Critical - Access bypass - SA-CONTRIB-2024-073EPSS 0.3%CVE-2025-65925MEDIUMAn issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to be created without EPSS 0.3%CVE-2025-1880LOWi-Drive i11/i12 Device Pairing authentication bypassEPSS 0.3%CVE-2024-27835LOWThis issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical accesEPSS 0.3%CVE-2025-31264MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS EPSS 0.3%CVE-2023-43660MEDIUMSSH key password bypassed in warpgateEPSS 0.3%CVE-2026-14541HIGHAuthentication Bypass and Audience Confusion in MCP Toolbox OAuth ProviderEPSS 0.3%CVE-2026-0408MEDIUMPath traversal vulnerability in Netgear WiFi Range ExtendersEPSS 0.3%CVE-2026-16892MEDIUMIBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service []EPSS 0.3%CVE-2025-41110HIGHImproper Authentication vulnerability in Ghost Robotics' Vision 60EPSS 0.3%