Fallos del tipo CWE-287

2410 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2017-15135It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly EPSS 3.8%CVE-2017-2628curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it didEPSS 3.8%CVE-2002-2438TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded byEPSS 3.7%CVE-2021-20020A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.EPSS 3.7%CVE-2021-26638HIGHXi Smarthome wallpad authentication bypass vulnerabilityEPSS 3.7%CVE-2021-36306HIGHNetworking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability. A remote unautheEPSS 3.7%CVE-2022-47003CRITICALA vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web requestEPSS 3.6%CVE-2021-37624HIGHFreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofingEPSS 3.6%CVE-2018-0321A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote MeEPSS 3.6%CVE-2022-0730Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.EPSS 3.5%CVE-2021-24148MStore API < 3.2.0 - Authentication Bypass With Sign In With AppleEPSS 3.4%CVE-2019-16028CRITICALCisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass VulnerabilityEPSS 3.4%CVE-2014-0760Festo CECX-X-(C1/M1) Controller Improper AuthenticationEPSS 3.3%CVE-2017-7562MEDIUMAn authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A EPSS 3.3%CVE-2025-66039CRITICALFreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth HeaderEPSS 3.3%CVE-2022-30995CRITICALSensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, LinEPSS 3.3%CVE-2023-0905HIGHSourceCodester Employee Task Management System changePasswordForEmployee.php improper authenticationEPSS 3.2%CVE-2017-12236A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthentEPSS 3.1%CVE-2026-59208HIGHn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity ResolutionEPSS 3.1%CVE-2023-30869CRITICALWordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege EscalationEPSS 3.1%