Fallos del tipo CWE-287

2454 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-41737HIGHIBM Spectrum Scale security bypassEPSS 0.1%CVE-2026-10548MEDIUMNousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authenticationEPSS 0.1%CVE-2026-20752MEDIUMImproper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System soEPSS 0.1%CVE-2022-39899MEDIUMImproper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input evenEPSS 0.1%CVE-2022-48305MEDIUMThere is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of tEPSS 0.1%CVE-2025-64432MEDIUMKubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation LayerEPSS 0.1%CVE-2019-6198HIGHA vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.EPSS 0.1%CVE-2019-6197HIGHA vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.EPSS 0.1%CVE-2025-68712MEDIUMSpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentiEPSS 0.1%CVE-2026-97846MEDIUMKeycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key bindingEPSS 0.1%CVE-2025-6723MEDIUMUntrusted user data can lead to privilege escalationEPSS 0.1%CVE-2025-71057HIGHImproper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attEPSS 0.1%CVE-2023-21471MEDIUMImproper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system pEPSS 0.1%CVE-2026-20891MEDIUMImproper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation ofEPSS 0.1%CVE-2026-13208MEDIUMKubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request bodyEPSS 0.1%CVE-2026-47166MEDIUMImageMagick: Heap Buffer Over-Read in distributed pixel cache serverEPSS 0.1%CVE-2022-41590MEDIUMSome smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful explEPSS 0.1%CVE-2023-24852HIGHImproper Authentication in CoreEPSS 0.1%CVE-2020-9250LOWThere is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software pacEPSS 0.1%CVE-2025-6044MEDIUMAn Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices aEPSS 0.1%