Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2019-18318A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2019-18317A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2019-18319A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2024-30299CRITICALTenable Vulnerability Disclosure | API Auth BypassEPSS 1.1%CVE-2023-41264CRITICALNetwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, lEPSS 1.0%CVE-2020-16102HIGHImproper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invaEPSS 1.0%CVE-2022-45174CRITICALAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under thEPSS 1.0%CVE-2021-32794MEDIUMAccidental removal of IPCPassword (< 5.1.2.4)EPSS 1.0%CVE-2022-45173CRITICALAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskEPSS 1.0%CVE-2022-29883MEDIUMA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pagEPSS 1.0%CVE-2026-78167CRITICALEFM ipTIME T16000M Session Validation httpcon_check_session_url improper authenticationEPSS 1.0%CVE-2022-34379CRITICALDell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of theEPSS 1.0%CVE-2023-2586CRITICAL Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices EPSS 1.0%CVE-2023-31007NONEApache Pulsar: Broker does not always disconnect client when authentication data expiresEPSS 1.0%CVE-2023-27582CRITICALFull authentication bypass if SASL authorization username is specifiedEPSS 1.0%CVE-2026-12773MEDIUMBerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authenticationEPSS 1.0%CVE-2024-36264CRITICALApache Submarine Commons Utils: default secretEPSS 1.0%CVE-2022-31685CRITICALVMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to WorkspaEPSS 1.0%CVE-2022-24813MEDIUMAuthentication Bypass Using an Alternate Path or Channel in CreateWikiEPSS 1.0%CVE-2023-50275HIGHHPE OneView may allow clusterService Authentication Bypass resulting in denial of service.EPSS 1.0%