Fallos del tipo CWE-287

2453 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-20924MEDIUMIn (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of prEPSS 0.2%CVE-2026-45153MEDIUMNextcloud: PIN bypass in PassCodeActivity via back buttonEPSS 0.2%CVE-2022-22283LOWImproper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.EPSS 0.2%CVE-2025-25451MEDIUMAn issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the "2fa_autEPSS 0.2%CVE-2026-43766MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOSEPSS 0.2%CVE-2026-78560MEDIUMImproper Authentication Validation in Okta Access Gateway Pass-Through Authentication SourceEPSS 0.2%CVE-2026-53514HIGHBetter Auth: Unauthorized invitation acceptance via unverified email match in organization pluginEPSS 0.2%CVE-2022-34380CRITICALDell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privEPSS 0.2%CVE-2026-12586HIGHLenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password ResetEPSS 0.2%CVE-2025-68931HIGHJervis has AES CBC Mode Without AuthenticationEPSS 0.2%CVE-2025-46590MEDIUMBypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypasEPSS 0.2%CVE-2023-0209HIGHNVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA is missing, which mayEPSS 0.2%CVE-2023-32661MEDIUMImproper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version EPSS 0.2%CVE-2022-47974MEDIUMThe Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the BlueEPSS 0.2%CVE-2023-2638MEDIUMRockwell Automation FactoryTalk System Services Vulnerable to a Denial-of-Service AttackEPSS 0.2%CVE-2022-48314MEDIUMThe Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerabEPSS 0.2%CVE-2021-25506MEDIUMNon-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial oEPSS 0.2%CVE-2022-21794HIGHImproper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits befEPSS 0.2%CVE-2026-49852HIGHjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)EPSS 0.2%CVE-2026-47838MEDIUMUnauthorized User Impersonation when Using X.509 Client CertificatesEPSS 0.2%