Fallos del tipo CWE-287

2418 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2020-8267A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was usingEPSS 1.3%CVE-2024-22245CRITICALArbitrary Authentication Relay Vulnerability in Deprecated EAP Browser PluginEPSS 1.3%CVE-2026-4252CRITICALTenda AC8 IPv6 check_is_ipv6 ip address for authenticationEPSS 1.3%CVE-2023-37471CRITICALUser impersonation using SAMLv1.x SSO in Open Access Management EPSS 1.3%CVE-2018-0195A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and uEPSS 1.3%CVE-2021-39196HIGHAuthenticated non-privileged user can request unfiltered data without adequate permissions in pcaptureEPSS 1.3%CVE-2022-2553The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a resulEPSS 1.3%CVE-2023-0773CRITICALUnauthorized Access Control Vulnerability in Uniview IP CameraEPSS 1.3%CVE-2024-45115CRITICALAdobe Commerce | Improper Authentication (CWE-287)EPSS 1.3%CVE-2024-36132HIGHInsufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access EPSS 1.2%CVE-2023-45038MEDIUMMusic StationEPSS 1.2%CVE-2023-48228HIGHOAuth2: PKCE can be fully circumventedEPSS 1.2%CVE-2007-1966CRITICALSession fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookiEPSS 1.2%CVE-2021-39215HIGHAuthentication Bypass: Forged Tokens Allow Access to Arbitrary RoomsEPSS 1.2%CVE-2021-22858HIGHChanGate EnterPrise Co., Ltd property management system - Broken AuthenticationEPSS 1.2%CVE-2018-3775Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 FEPSS 1.2%CVE-2023-24831CRITICALApache IoTDB grafana-connector Login Bypass VulnerabilityEPSS 1.2%CVE-2026-26119HIGHWindows Admin Center Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2023-6248CRITICALData leakage and arbitrary remote code execution in Syrus cloud devicesEPSS 1.2%CVE-2024-6248HIGHWyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution VulnerabilityEPSS 1.2%