Fallos del tipo CWE-287

2410 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2021-1571HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 9.7%CVE-2025-9533MEDIUMTOTOLINK T10 formLoginAuth.htm improper authenticationEPSS 9.4%CVE-2021-1543HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 9.3%CVE-2012-6440MEDIUMRockwell Automation ControlLogix PLC Improper Input ValidationEPSS 9.3%CVE-2016-2125MEDIUMIt was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A servEPSS 9.2%CVE-2025-44005CRITICALAn attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain pEPSS 9.1%CVE-2021-1541HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 8.8%CVE-2018-10682CRITICALAn issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without EPSS 8.3%CVE-2021-39165HIGHUnauthenticated SQL InjectionEPSS 8.2%CVE-2025-59934CRITICALFormbricks missing JWT signature verificationEPSS 8.1%CVE-2012-6437CRITICALRockwell Automation ControlLogix PLC Improper AuthenticationEPSS 7.8%CVE-2018-14826Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with EPSS 7.7%CVE-2025-53786HIGHMicrosoft Exchange Server Hybrid Deployment Elevation of Privilege VulnerabilityEPSS 7.7%CVE-2026-82329CRITICALPotential authentication bypass leading to administrative access in ArtifactoryEPSS 7.7%KEVCVE-2021-24527Profile Builder < 3.4.9 - Admin Access via Password ResetEPSS 7.6%CVE-2018-7532Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IPEPSS 7.6%CVE-2024-5805CRITICALMOVEit Gateway Authentication Bypass VulnerabilityEPSS 7.6%CVE-2025-4755MEDIUMD-Link DI-7003GV2 netconfig.asp sub_497DE4 improper authenticationEPSS 7.3%CVE-2025-46631MEDIUMImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable tEPSS 7.2%CVE-2021-42949CRITICALThe component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackEPSS 7.1%