Fallos del tipo CWE-287

2398 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-63224CRITICALThe Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers cEPSS 0.7%CVE-2024-1006HIGHShanxi Diankeyun Technology NODERP Cookie common.php improper authenticationEPSS 0.7%CVE-2026-20129CRITICALCisco Catayst SD-WAN Authentication Bypass VulnerabilityEPSS 0.7%CVE-2024-24830CRITICALOpenObserve Privilege Escalation Vulnerability in Users APIEPSS 0.7%CVE-2023-34246MEDIUMDoorkeeper Improper Authentication vulnerabilityEPSS 0.7%CVE-2017-12281A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of EPSS 0.7%CVE-2026-29145CRITICALApache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabledEPSS 0.7%CVE-2017-20133HIGHItech Job Portal Script admin improper authenticationEPSS 0.7%CVE-2022-2533MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2EPSS 0.7%CVE-2025-24032CRITICALPAM-PKCS#11 vulnerable to authentication bypass with default value for `cert_policy` (`none`)EPSS 0.7%CVE-2017-7937An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to EPSS 0.7%CVE-2024-10173MEDIUMdidi DDMQ Console Module improper authenticationEPSS 0.7%CVE-2023-33190CRITICALImproperly configured permissions in SealosEPSS 0.7%CVE-2025-4494MEDIUMJAdmin-JAVA JAdmin Admin Backend NoNeedLoginController.java toLogin improper authenticationEPSS 0.7%CVE-2026-16209MEDIUMGerapy Project Upload Endpoint views.py missing authenticationEPSS 0.7%CVE-2025-7955CRITICALRingCentral Communications 1.5 - 1.6.8 - Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify FunctionEPSS 0.7%CVE-2024-4303HIGH ArmorX Android APP - MFA BypassEPSS 0.7%CVE-2026-62825CRITICALAzure Key Vault Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-36133CRITICALThe WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.EPSS 0.7%CVE-2023-22278MEDIUMm-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to byEPSS 0.7%