Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2019-14880MEDIUMA vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not EPSS 1.1%CVE-2023-52161HIGHThe Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthEPSS 1.1%CVE-2025-37093CRITICALAn authentication bypass vulnerability exists in HPE StoreOnce Software.EPSS 1.1%CVE-2022-38119CRITICALPOWERCOM CO., LTD. UPSMON PRO - Broken AuthenticationEPSS 1.1%CVE-2022-20733MEDIUMCisco Identity Services Engine Authentication Bypass VulnerabilityEPSS 1.1%CVE-2023-2024CRITICALImproper Authentication for OpenBlue Enterprise Manager Data CollectorEPSS 1.1%CVE-2018-0435Cisco Umbrella API Unauthorized Access VulnerabilityEPSS 1.1%CVE-2023-29032HIGHApache OpenMeetings: allows bypass authenticationEPSS 1.1%CVE-2022-2765MEDIUMSourceCodester Company Website CMS settings improper authenticationEPSS 1.1%CVE-2021-41126HIGHDeleted Admin Can Sign In to Admin InterfaceEPSS 1.1%CVE-2020-16098CRITICALIt is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8EPSS 1.1%CVE-2021-3827A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behaviEPSS 1.1%CVE-2026-53913CRITICALApache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is acceptedEPSS 1.1%CVE-2025-11942MEDIUM70mai X200 Pairing missing authenticationEPSS 1.1%CVE-2024-23629CRITICALMotorola MR2600 Authentication Bypass VulnerabilityEPSS 1.1%CVE-2022-42458CRITICALAuthentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticatEPSS 1.1%CVE-2019-18312A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.1%CVE-2019-14909CRITICALA vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or vEPSS 1.1%CVE-2025-7862MEDIUMTOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authenticationEPSS 1.1%CVE-2017-12712The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and EPSS 1.1%