Fallos del tipo CWE-287

2418 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2021-38412CRITICALDigi PortServer TS 16 Improper AuthenticationEPSS 1.3%CVE-2019-3798MEDIUMEscalation of Privileges in Cloud ControllerEPSS 1.3%CVE-2019-10966In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal EPSS 1.3%CVE-2023-24830HIGHApache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorizationEPSS 1.3%CVE-2020-8200Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active DirecEPSS 1.3%CVE-2008-3738CRITICALSession fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectorEPSS 1.3%CVE-2021-40851HIGHTCMAN GIM SQL injection vulnerabilityEPSS 1.3%CVE-2025-6763CRITICALComet System H3531 Web-based Management setupA.cfg missing authenticationEPSS 1.3%CVE-2020-2018CRITICALPAN-OS: Panorama authentication bypass vulnerabilityEPSS 1.3%CVE-2016-0796WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and EPSS 1.3%CVE-2020-14494OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexitEPSS 1.3%CVE-2022-2141CRITICALICSA-22-200-01 MiCODUS MV720 GPS tracker Improper AuthenticationEPSS 1.3%CVE-2020-27254Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to impEPSS 1.3%CVE-2021-41265HIGHImproper Authentication in Flask-AppBuilderEPSS 1.3%CVE-2024-38099MEDIUMWindows Remote Desktop Licensing Service Denial of Service VulnerabilityEPSS 1.3%CVE-2018-4856A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative accessEPSS 1.3%CVE-2019-12254CRITICALTECSON/GOK: Improper Authentication and Access Control on multiple devicesEPSS 1.3%CVE-2026-36829CRITICALAn authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validateEPSS 1.3%CVE-2024-21390HIGHMicrosoft Authenticator Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2020-14504MEDIUMThe web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attackeEPSS 1.3%