Fallos del tipo CWE-287

2417 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2021-31349CRITICALSession Smart Router: Authentication Bypass VulnerabilityEPSS 1.7%CVE-2023-2706HIGHOTP Login Woocommerce & Gravity Forms <= 2.2 - Authentication Bypass to Privilege EscalationEPSS 1.7%CVE-2020-25165BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products arEPSS 1.7%CVE-2021-21378HIGHJWT authentication bypass with unknown issuer tokenEPSS 1.7%CVE-2021-43445CRITICALONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service oEPSS 1.7%CVE-2020-8253Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10EPSS 1.7%CVE-2022-35925MEDIUMMissing rate limit in Authentication in bookwyrmEPSS 1.7%CVE-2020-25719A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DCEPSS 1.7%CVE-2021-36368LOWAn issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=vEPSS 1.7%CVE-2019-20464HIGHAn issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to strEPSS 1.7%CVE-2022-23635HIGHUnauthenticated control plane denial of service attack in IstioEPSS 1.7%CVE-2019-14856MEDIUMansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a NoneEPSS 1.7%CVE-2021-21335MEDIUMBasic Authentication can be bypassed using a malformed usernameEPSS 1.7%CVE-2018-5387Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be aEPSS 1.7%CVE-2018-3761Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowEPSS 1.7%CVE-2025-26326HIGHA vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which aEPSS 1.6%CVE-2020-15136MEDIUMImproper authentication in etcdEPSS 1.6%CVE-2019-15585Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitEPSS 1.6%CVE-2026-12571CRITICALAuthentication Bypass Leading to Account TakeoverEPSS 1.6%CVE-2022-22935LOWAn issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MEPSS 1.6%