Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2021-32753HIGHWeak password in API gateway in EdgeX Foundry Edinburgh, Fuji, Geneva, and Hanoi releases allows remote attackers to obtain authentication token via dictionary-based password attack when OAuth2 authentication method is enabled.EPSS 0.8%CVE-2023-23612MEDIUMIssue with whitespace in JWT roles in OpenSearchEPSS 0.8%CVE-2020-25183HIGHMedtronic MyCareLink Smart Improper AuthenticationEPSS 0.8%CVE-2026-12795MEDIUMBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationEPSS 0.8%CVE-2024-3263CRITICALImproper authentication in YMS VIS ProEPSS 0.8%CVE-2023-39196MEDIUMApache Ozone: Missing mutual TLS authentication in one of the service internal Ozone Storage Container Manager endpointsEPSS 0.8%CVE-2026-1203MEDIUMCRMEB JSON Token LoginServices.php remoteRegister improper authenticationEPSS 0.8%CVE-2026-49003CRITICALUnauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 ProductEPSS 0.8%CVE-2020-14380An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant externEPSS 0.8%CVE-2025-15099MEDIUMsimstudioai sim CRON Secret internal.ts improper authenticationEPSS 0.8%CVE-2026-82693CRITICALTenda AC1206 Web UI telnet TendaTelnet missing authenticationEPSS 0.8%CVE-2022-32514CRITICALA CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web pEPSS 0.8%CVE-2018-17926The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicioEPSS 0.8%CVE-2023-1464HIGHSourceCodester Medicine Tracker System improper authenticationEPSS 0.8%CVE-2024-10111HIGHOAuth Single Sign On – SSO (OAuth Client) <= 6.26.3 - Authentication BypassEPSS 0.8%CVE-2023-24093CRITICALAn access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.EPSS 0.8%CVE-2017-12213A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches couEPSS 0.8%CVE-2023-21817HIGHWindows Kerberos Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-14714MEDIUMzhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authenticationEPSS 0.8%CVE-2023-3065CRITICALMobatime mobile application - Authentication bypassEPSS 0.8%