Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-24738HIGHAccount compromise in EvmosEPSS 1.1%CVE-2015-10083MEDIUMharrystech Dynosaur-Rails application_controller.rb basic_auth improper authenticationEPSS 1.1%CVE-2019-18320A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2022-40602CRITICALA flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an imprEPSS 1.1%CVE-2020-15269HIGHExpired token reuse in SpreeEPSS 1.1%CVE-2022-39249HIGHMatrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessionsEPSS 1.1%CVE-2024-20738CRITICALAdobe FrameMaker Publishing Server Authentication Bypass Vulnerability | CVE-2023-44324 bypassEPSS 1.1%CVE-2023-2283A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signaturEPSS 1.1%CVE-2018-0116A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized aEPSS 1.1%CVE-2021-33539HIGHWEIDMUELLER: WLAN devices affected by authentication bypass vulnerabilityEPSS 1.1%CVE-2022-25027HIGHThe Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricEPSS 1.1%CVE-2023-39349HIGHSentry vulnerable to privilege escalation via ApiTokensEndpointEPSS 1.1%CVE-2025-4268MEDIUMTOTOLINK A720R cstecgi.cgi missing authenticationEPSS 1.1%CVE-2025-64513CRITICALMilvus Proxy has Critical Authentication Bypass VulnerabilityEPSS 1.1%CVE-2020-8148UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicEPSS 1.1%CVE-2019-14910CRITICALA vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS froEPSS 1.1%CVE-2022-44244MEDIUMAn authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.EPSS 1.1%CVE-2026-23906CRITICALApache Druid: Authentication Bypass via LDAP Anonymous BindEPSS 1.1%CVE-2022-36092HIGHXWiki Platform Old Core vulnerable to Authentication Bypass Using the Login ActionEPSS 1.1%CVE-2022-43620HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. AutEPSS 1.1%