Fallos del tipo CWE-287

2418 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2020-36533LOWKlapp App JSON Web Token improper authenticationEPSS 1.5%CVE-2023-29463HIGHPavilion8 Security Misconfiguration VulnerabilityEPSS 1.5%CVE-2020-8272Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8EPSS 1.5%CVE-2022-39042CRITICALaEnrich a+HRD - Improper AuthenticationEPSS 1.5%CVE-2026-44551CRITICALOpen WebUI: LDAP Empty Password Authentication BypassEPSS 1.5%CVE-2021-21329HIGHMulti Factor Authentication Token Improperly Validated On User LoginEPSS 1.5%CVE-2019-6832A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formeEPSS 1.5%CVE-2019-1724HIGHCisco Small Business RV320 and RV325 Routers Session Hijacking VulnerabilityEPSS 1.5%CVE-2023-47504MEDIUMWordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerabilityEPSS 1.5%CVE-2025-1723HIGHAccount takeoverEPSS 1.4%CVE-2021-23847CRITICALUnauthenticated Information Extraction VulnerabilityEPSS 1.4%CVE-2022-31013CRITICALAuthentication bypass in Vartalap chat-serverEPSS 1.4%CVE-2019-1946MEDIUMCisco Enterprise NFV Infrastructure Software Web-Based Management Interface Authentication Bypass VulnerabilityEPSS 1.4%CVE-2022-43504MEDIUMImproper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email addrEPSS 1.4%CVE-2023-41999CRITICALArcserve UDP Management Authentication Bypass EPSS 1.4%CVE-2022-37913CRITICALVulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.4%CVE-2022-37914CRITICALVulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.4%CVE-2023-34340CRITICALApache Accumulo: Accumulo 2.1.0 may incorrectly validate cached credentialsEPSS 1.4%CVE-2021-39177HIGHUser impersonation due to incorrect handling of the login JWTEPSS 1.4%CVE-2019-19104CRITICALABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access ControlEPSS 1.4%