Fallos del tipo CWE-287

2410 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2017-12698An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a pEPSS 4.8%CVE-2018-14805ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key valEPSS 4.8%CVE-2025-25205HIGHRemote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matchingEPSS 4.8%CVE-2017-14002GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentiEPSS 4.7%CVE-2019-0543HIGHAn elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of EPSS 4.7%KEVCVE-2017-11427HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 4.7%CVE-2026-24294HIGHWindows SMB Server Elevation of Privilege VulnerabilityEPSS 4.7%CVE-2019-1938CRITICALCisco UCS Director and Cisco UCS Director Express for Big Data API Authentication Bypass VulnerabilityEPSS 4.6%CVE-2019-1974CRITICALCisco IMC Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass VulnerabilityEPSS 4.5%CVE-2024-0799CRITICALAuthentication Bypass via wizardLogin in Arcserve Unified Data ProtectionEPSS 4.3%CVE-2010-4478CRITICALOpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remotEPSS 4.2%CVE-2021-36346MEDIUMDell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially expEPSS 4.2%CVE-2017-6868An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attaEPSS 4.2%CVE-2023-22893HIGHStrapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for auEPSS 4.1%CVE-2017-3791A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and executEPSS 4.1%CVE-2018-16886MEDIUMetcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control EPSS 4.0%CVE-2024-47533CRITICALCobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changesEPSS 4.0%CVE-2023-4568MEDIUMPaperCut NG Unauthenticated XMLRPCEPSS 3.9%CVE-2026-48611CRITICALImproper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to uEPSS 3.9%CVE-2022-3477CRITICALtagDiv Composer < 3.5 - Unauthenticated Account TakeoverEPSS 3.8%