Fallos del tipo CWE-287

2420 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-11186CRITICALOn affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premEPSS 0.8%CVE-2020-20402HIGHWestbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.EPSS 0.7%CVE-2025-46548MEDIUMApache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effectiveEPSS 0.7%CVE-2022-35726MEDIUMWordPress Video Gallery plugin <= 1.3.4.5 - Broken Authentication vulnerabilityEPSS 0.7%CVE-2023-37283HIGHAuthentication Bypass via HTML Form & Identifier First AdapterEPSS 0.7%CVE-2024-22394CRITICALAn improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow EPSS 0.7%CVE-2026-82694CRITICALTenda AC1206 Web UI ate R7WebsSecurityHandler missing authenticationEPSS 0.7%CVE-2023-6787MEDIUMKeycloak: session hijacking via re-authenticationEPSS 0.7%CVE-2021-38679MEDIUMImproper Authentication in Kazoo ServerEPSS 0.7%CVE-2025-63216CRITICALThe Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers EPSS 0.7%CVE-2024-28012CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2026-82695CRITICALTenda AC18 Telnet telnet missing authenticationEPSS 0.7%CVE-2018-16496In Versa Director, the un-authentication request found.EPSS 0.7%CVE-2024-33110CRITICALD-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.EPSS 0.7%CVE-2022-43549CRITICALImproper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.EPSS 0.7%CVE-2022-2533MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2EPSS 0.7%CVE-2026-23813CRITICALAuthentication Bypass in Web Interface allows Unauthenticated Admin Password ResetEPSS 0.7%CVE-2023-21841HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.7%CVE-2024-12264CRITICALPayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege EscalationEPSS 0.7%CVE-2026-32136CRITICALAdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication BypassEPSS 0.7%