Fallos del tipo CWE-287

2455 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-10684MEDIUMConstruction Light < 1.6.8 - Subscriber+ Arbitrary Plugin ActivationEPSS 0.1%CVE-2022-25832MEDIUMImproper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app withouEPSS 0.1%CVE-2021-25347MEDIUMHijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the providerEPSS 0.1%CVE-2026-20655MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOEPSS 0.1%CVE-2024-40653HIGHIn multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a loEPSS 0.1%CVE-2023-2626HIGHAuthentication Bypass in OpenThread Boarder Router devicesEPSS 0.1%CVE-2021-25389LOWImproper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.EPSS 0.1%CVE-2022-25816MEDIUMImproper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable withoEPSS 0.1%CVE-2022-25833LOWImproper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permiEPSS 0.1%CVE-2021-25484MEDIUMImproper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.EPSS 0.1%CVE-2024-42038HIGHVulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect serviceEPSS 0.1%CVE-2018-11952HIGHImproper Authentication in TrustZoneEPSS 0.1%CVE-2022-25817MEDIUMImproper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.EPSS 0.1%CVE-2022-30755HIGHImproper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijaEPSS 0.1%CVE-2026-78236HIGHInsecure PIN derivation mechanism in Admin By Request (ABR)EPSS 0.1%CVE-2016-10394CRITICALImproper Authentication in CoreEPSS 0.1%CVE-2022-33689MEDIUMImproper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unEPSS 0.1%CVE-2026-56792MEDIUMDell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker withEPSS 0.1%CVE-2026-81473HIGHDell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker withEPSS 0.1%CVE-2022-33732MEDIUMImproper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PCEPSS 0.1%