Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2022-23555CRITICALauthentik vulnerable to Improper Authentication via invitation URL token reuseEPSS 0.9%CVE-2025-14746MEDIUMNingyuanda TC155 RTSP Live Video Stream Endpoint improper authenticationEPSS 0.9%CVE-2025-27641CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-SigEPSS 0.9%CVE-2023-21721MEDIUMMicrosoft OneNote Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-22334MEDIUMUse of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remotEPSS 0.9%CVE-2020-11101CRITICALSierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login sessiEPSS 0.9%CVE-2021-28494CRITICALIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication iEPSS 0.9%CVE-2025-34186CRITICALIlevia EVE X1/X5 Server 4.7.18.0.eden Authentication BypassEPSS 0.9%CVE-2023-28609CRITICALapi/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.EPSS 0.9%CVE-2026-59822HIGHLiteLLM: MCP Authentication Bypass via OAuth2 Passthrough FallbackEPSS 0.9%KEVCVE-2020-15222HIGHReplay of private_key_jwt possible in ORY FositeEPSS 0.9%CVE-2022-31083HIGHAuthentication bypass in Parse Server Apple Game Center auth adapter EPSS 0.9%CVE-2023-35137HIGHAn improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwEPSS 0.9%CVE-2025-48370LOWauth-js Vulnerable to Insecure Path Routing from Malformed User InputEPSS 0.9%CVE-2023-49340CRITICALAn issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privilegEPSS 0.9%CVE-2011-2054MEDIUMCisco ASA Secondary Authentication Bypass VulnerabilityEPSS 0.9%CVE-2025-6916HIGHTOTOLINK T6 formLoginAuth.htm Form_Login missing authenticationEPSS 0.9%CVE-2024-25128CRITICALFlask-AppBuilder incorrect authentication when using auth type OpenID EPSS 0.9%CVE-2022-21695MEDIUMImproper Access Control in OnionshareEPSS 0.9%CVE-2023-31634CRITICALIn TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP EPSS 0.9%