Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2018-0247A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco EPSS 0.9%CVE-2023-0311MEDIUMImproper Authentication in thorsten/phpmyfaqEPSS 0.9%CVE-2023-40660MEDIUMOpensc: potential pin bypass when card tracks its own login stateEPSS 0.9%CVE-2021-37172A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate agEPSS 0.9%CVE-2024-6057CRITICALImproper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that EPSS 0.9%CVE-2025-2339MEDIUMotale Tale Blog logs improper authenticationEPSS 0.9%CVE-2022-2662CRITICALSequi PortBloque S Improper AuthenticationEPSS 0.9%CVE-2021-26073HIGHBroken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js pacEPSS 0.9%CVE-2023-20214CRITICALA vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, rEPSS 0.9%CVE-2022-36960HIGHSolarWinds Platform Improper Input ValidationEPSS 0.9%CVE-2023-34388MEDIUMImproper authentication could lead to session hijackingEPSS 0.9%CVE-2021-44056HIGHImproper authentication in Video StationEPSS 0.9%CVE-2021-44057HIGHImproper authentication in Photo StationEPSS 0.9%CVE-2024-46434HIGHTenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gainEPSS 0.9%CVE-2023-5970Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external dEPSS 0.9%CVE-2024-34103HIGHCustomer account takeover via web API call & subsequent password resetEPSS 0.9%CVE-2024-39340HIGHThe authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enablEPSS 0.9%CVE-2025-2771MEDIUMBEC Technologies Multiple Routers Authentication Bypass VulnerabilityEPSS 0.9%CVE-2026-32173HIGHAzure SRE Agent Information Disclosure VulnerabilityEPSS 0.9%CVE-2022-39229MEDIUMGrafana users with email as a username can block other users from signing inEPSS 0.9%