Fallos del tipo CWE-287

2454 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-21460MEDIUMImproper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.EPSS 0.2%CVE-2025-48909HIGHBypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentialiEPSS 0.2%CVE-2024-36266HIGHA vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authenEPSS 0.2%CVE-2024-38825MEDIUMCVE-2024-38825 Salt AdvisoryEPSS 0.2%CVE-2022-48575LOWA person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issueEPSS 0.2%CVE-2025-61679HIGHAnyquery Unauthenticated Access Vulnerability Exposes Private Integration DataEPSS 0.2%CVE-2026-15384MEDIUMManual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOREPSS 0.2%CVE-2023-21425MEDIUMImproper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive informaEPSS 0.2%CVE-2023-21437MEDIUMImproper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive informEPSS 0.2%CVE-2023-21484MEDIUMImproper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to executeEPSS 0.1%CVE-2024-24279HIGHAn issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated EPSS 0.1%CVE-2026-20885HIGHImproper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosuEPSS 0.1%CVE-2026-1568CRITICALRapid7 InsightVM Signature Validation VulnerabilityEPSS 0.1%CVE-2025-43281HIGHThe issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate theEPSS 0.1%CVE-2023-21487MEDIUMImproper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call settingEPSS 0.1%CVE-2023-41751MEDIUMSensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) bEPSS 0.1%CVE-2023-33070HIGHImproper Authentication in Automotive OSEPSS 0.1%CVE-2022-33242HIGHImproper authentication in Qualcomm IPCEPSS 0.1%CVE-2025-53169HIGHVulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this EPSS 0.1%CVE-2025-25201MEDIUMImproper Validation of Admin Key in PIV SmartcardEPSS 0.1%