Fallos del tipo CWE-287

2410 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2021-4073CRITICALRegistrationMagic <= 5.0.1.7 Authentication BypassEPSS 7.0%CVE-2025-63207CRITICALThe R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentEPSS 7.0%CVE-2026-41276HIGHFlowise: AccountService resetPassword Authentication Bypass VulnerabilityEPSS 6.9%CVE-2023-37266CRITICALWeak json web token (JWT) secrets in CasaOSEPSS 6.8%CVE-2017-12337A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could aEPSS 6.4%CVE-2020-12145MEDIUMSilver Peak Unity OrchestratorTM authentication can be subverted through manipulation of HTTP headers.EPSS 6.0%CVE-2022-39290HIGHCSRF key bypass using HTTP methods in zoneminderEPSS 6.0%CVE-2021-21513HIGHDell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configEPSS 5.9%CVE-2022-0715HIGHA CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a keEPSS 5.8%CVE-2025-10365CRITICALAuthentication Bypass in Evertz SDVNEPSS 5.6%CVE-2022-0492HIGHA vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certaEPSS 5.5%KEVCVE-2017-6747A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypaEPSS 5.5%CVE-2021-34993CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. AuthenticationEPSS 5.4%CVE-2019-1917CRITICALCisco Vision Dynamic Signage Director REST API Authentication Bypass VulnerabilityEPSS 5.3%CVE-2019-12643CRITICALCisco REST API Container for IOS XE Software Authentication Bypass VulnerabilityEPSS 5.3%CVE-2017-12229A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, reEPSS 5.2%CVE-2017-16748An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and priEPSS 5.1%CVE-2018-0238A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenEPSS 5.1%CVE-2018-10611Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to alEPSS 5.0%CVE-2012-5864Sinapsi eSolar Improper AuthenticationEPSS 4.9%