Fallos del tipo CWE-287

2417 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-28992HIGHSolarWinds Access Rights Manager Directory Traversal and Information Disclosure VulnerabilityEPSS 1.9%CVE-2021-22764MEDIUMA CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (seEPSS 1.9%CVE-2021-26637HIGHSiHAS Improper Authentication vulnerabilityEPSS 1.9%CVE-2021-32637CRITICALAuthentication bypassed with malformed request URIEPSS 1.9%CVE-2017-14006GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-codedEPSS 1.9%CVE-2017-14004GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful explEPSS 1.9%CVE-2021-21308MEDIUMImproper session management for soft logoutEPSS 1.9%CVE-2017-12695An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitationEPSS 1.9%CVE-2017-6047Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessible without authenticEPSS 1.8%CVE-2018-0087A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to theEPSS 1.8%CVE-2018-15721The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote atEPSS 1.8%CVE-2018-4836A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleCEPSS 1.8%CVE-2025-30282CRITICALColdFusion | Improper Authentication (CWE-287)EPSS 1.8%CVE-2021-43999Improper validation of SAML responsesEPSS 1.8%CVE-2019-1662HIGHCisco Prime Collaboration Assurance Software Unauthenticated Access VulnerabilityEPSS 1.8%CVE-2016-2124A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent oEPSS 1.8%CVE-2020-4074HIGHImproper AuthenticationEPSS 1.8%CVE-2017-14026In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allEPSS 1.8%CVE-2021-41157MEDIUMFreeSWITCH does not authenticate SIP SUBSCRIBE requests by defaultEPSS 1.7%CVE-2021-21538CRITICALDell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthentEPSS 1.7%