Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2020-15164CRITICALAuthentication Bypass in Scratch Login (mediawiki-scratch-login)EPSS 1.2%CVE-2024-23470CRITICALSolarWinds Access Rights Manager (ARM) UserScriptHumster Exposed Dangerous Method Remote Command Execution VulnerabilityEPSS 1.2%CVE-2022-38744HIGHFactoryTalk Alarm and Events Server Vulnerable to Denial-Of-Service AttackEPSS 1.2%CVE-2018-25043MEDIUMuTorrent PRNG improper authenticationEPSS 1.2%CVE-2026-22594HIGHGhost has Staff 2FA bypassEPSS 1.1%CVE-2025-21349MEDIUMWindows Remote Desktop Configuration Service Tampering VulnerabilityEPSS 1.1%CVE-2022-34839MEDIUMWordPress WP OAuth2 Server plugin <= 1.0.1 - Authentication Bypass vulnerabilityEPSS 1.1%CVE-2022-24857HIGHMulti factor authentication bypass in django-mfa3EPSS 1.1%CVE-2025-30430CRITICALThis issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.EPSS 1.1%CVE-2024-51767HIGHAn authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.EPSS 1.1%CVE-2020-3410HIGHCisco Firepower Management Center Software Common Access Card Authentication Bypass VulnerabilityEPSS 1.1%CVE-2021-3632A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already rEPSS 1.1%CVE-2023-6342MEDIUMTyler Technologies Court Case Management Plus "pay for print" allows authentication bypassEPSS 1.1%CVE-2023-1778CRITICALDefault Credential Vulnerability in GajShield Data Security FirewallEPSS 1.1%CVE-2023-25601Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authenticationEPSS 1.1%CVE-2020-10916HIGHThis vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 85EPSS 1.1%CVE-2024-34340CRITICALAuthentication Bypass when using using older password hashesEPSS 1.1%CVE-2023-44302HIGH Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploiEPSS 1.1%CVE-2021-3046MEDIUMPAN-OS: Improper SAML Authentication Vulnerability in GlobalProtect PortalEPSS 1.1%CVE-2019-18906CRITICALcryptctl: client side password hashing is equivalent to clear text password storageEPSS 1.1%