Fallos del tipo CWE-287

2400 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2017-7546PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackersEPSS 61.6%CVE-2015-7755CRITICALJuniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 beforeEPSS 61.1%KEVCVE-2023-5830HIGHColumbiaSoft Document Locator WebTools login improper authenticationEPSS 60.8%CVE-2023-42442HIGHJumpServer session replays download without authenticationEPSS 58.5%CVE-2023-4415HIGHRuijie RG-EW1200G login improper authenticationEPSS 58.3%CVE-2022-24422CRITICALDell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticateEPSS 57.8%CVE-2021-27651CRITICALIn versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authenticaEPSS 53.8%CVE-2024-26331HIGHReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to EPSS 51.3%CVE-2024-2862CRITICALPassword reset vulnerability without authorization on LG LED AssistantEPSS 51.0%CVE-2020-12812CRITICALAn improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to logEPSS 49.3%KEVCVE-2023-50919CRITICALAn issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. ThEPSS 47.8%CVE-2021-22893CRITICALPulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share BrowseEPSS 47.2%KEVCVE-2024-8181CRITICALFlowise Authentication BypassEPSS 45.1%CVE-2024-3080CRITICALASUS Router - Improper AuthenticationEPSS 43.5%CVE-2023-49105CRITICALAn issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication EPSS 43.2%KEVCVE-2022-42233CRITICALTenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.EPSS 42.7%CVE-2021-37580Apache ShenYu Admin bypass JWT authenticationEPSS 41.9%CVE-2022-25369CRITICALAn issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists dEPSS 41.4%CVE-2025-32815MEDIUMAn issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.EPSS 39.7%CVE-2025-53778HIGHWindows NTLM Elevation of Privilege VulnerabilityEPSS 38.9%