Fallos del tipo CWE-287

2420 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-7401HIGHClient Enrollment Process BypassEPSS 0.8%CVE-2021-25466MEDIUMImproper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and EPSS 0.8%CVE-2022-39184CRITICALEXFO - BV-10 Performance Endpoint Unit Authentication bypassEPSS 0.8%CVE-2026-15192MEDIUMmettle sendportal APIv1 Webhooks mailjet missing authenticationEPSS 0.8%CVE-2022-41436CRITICALAn issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/EPSS 0.8%CVE-2025-4018MEDIUM20120630 Novel-Plus CrawlController.java addCrawlSource missing authenticationEPSS 0.8%CVE-2021-32543MEDIUMSysJust CTS Web - Broken AuthenticationEPSS 0.8%CVE-2022-44569HIGHA locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.EPSS 0.8%CVE-2022-24748MEDIUMIncorrect Authentication in shopwareEPSS 0.8%CVE-2025-4015MEDIUM20120630 Novel-Plus SessionController.java list missing authenticationEPSS 0.8%CVE-2026-56191CRITICALMicrosoft Exchange Online Tampering VulnerabilityEPSS 0.8%CVE-2022-47508HIGHDisable NTLM: SAM 2022.4 EPSS 0.8%CVE-2022-23541MEDIUMjsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMACEPSS 0.8%CVE-2021-25445Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in SamsuEPSS 0.8%CVE-2023-4501CRITICALAuthentication bypass in OpenText (Micro Focus) Enterprise ServerEPSS 0.8%CVE-2026-40139CRITICALCritical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote AccessEPSS 0.8%CVE-2023-32682MEDIUMImproper checks for deactivated users during login in synapseEPSS 0.8%CVE-2024-38139HIGHMicrosoft Dataverse Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-11186CRITICALOn affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premEPSS 0.8%CVE-2023-3622MEDIUMAccess Control Bypass Vulnerability in the SolarWinds Platform EPSS 0.8%