Fallos del tipo CWE-287

2415 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2026-21891CRITICALZimaOS has Authentication Bypass via System-Level UsernameEPSS 2.4%CVE-2024-37152MEDIUMUnauthenticated Access to sensitive settings in Argo CDEPSS 2.3%CVE-2020-7533CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication whEPSS 2.3%CVE-2021-25315CRITICALsalt-api unauthenticated remote code executionEPSS 2.3%CVE-2014-0769Festo CECX-X-(C1/M1) Controller Improper AuthenticationEPSS 2.3%CVE-2017-9625An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper auEPSS 2.3%CVE-2019-18314A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 2.3%CVE-2017-14000An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a speciEPSS 2.3%CVE-2021-35029CRITICALAn authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64EPSS 2.3%CVE-2023-28125MEDIUMAn improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access toEPSS 2.3%CVE-2022-41912CRITICALcrewjam/saml go library is vulnerable to signature bypass via multiple Assertion elementsEPSS 2.2%CVE-2022-21618MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that EPSS 2.2%CVE-2026-11387CRITICALSMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password ResetEPSS 2.2%CVE-2018-4835A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's poEPSS 2.2%CVE-2022-31020HIGHRemote code execution in Indy's NODE_UPGRADE transactionEPSS 2.2%CVE-2022-37298CRITICALShinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinEPSS 2.2%CVE-2022-22576HIGHAn improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connectiEPSS 2.2%CVE-2017-7934An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using oEPSS 2.1%CVE-2021-20288An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn'EPSS 2.1%CVE-2022-22990HIGHLimited authentication bypass vulnerability on Western Digital My Cloud devicesEPSS 2.1%