Fallos del tipo CWE-287

2398 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-29849CRITICALVeeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.EPSS 38.4%CVE-2019-6814A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impaEPSS 36.6%CVE-2019-19006CRITICALSangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.EPSS 36.6%KEVCVE-2024-57045CRITICALA vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authenEPSS 32.2%CVE-2025-68926CRITICALRustFS has a gRPC Hardcoded Token Authentication BypassEPSS 31.1%CVE-2019-1867CRITICALCisco Elastic Services Controller REST API Authentication Bypass VulnerabilityEPSS 30.3%CVE-2017-9946HIGHA vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker withEPSS 25.0%CVE-2024-21899CRITICALQTS, QuTS hero, QuTScloudEPSS 24.4%CVE-2026-45434CRITICALApache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCEEPSS 22.4%CVE-2024-6235CRITICALSensitive information disclosureEPSS 21.2%CVE-2025-49001HIGHDataease Authentication Bypass VulnerabilityEPSS 21.1%CVE-2025-4978CRITICALNetgear DGND3700 Basic Authentication BRS_top.html improper authenticationEPSS 21.0%CVE-2026-62144CRITICALManagement Authentication Bypass and Privilege EscalationEPSS 20.8%CVE-2022-31125CRITICALAuthentication Bypass in Roxy-wiEPSS 20.6%CVE-2017-3167In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentEPSS 20.2%CVE-2025-55234HIGHWindows SMB Elevation of Privilege VulnerabilityEPSS 20.1%CVE-2024-24496CRITICALAn issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php,EPSS 19.5%CVE-2025-54918HIGHWindows NTLM Elevation of Privilege VulnerabilityEPSS 19.4%CVE-2016-7836CRITICALSKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection withEPSS 19.2%KEVCVE-2026-41679CRITICALPaperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization BypassEPSS 18.9%