Fallos del tipo CWE-287

2449 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2024-30939MEDIUMAn issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control EPSS 0.4%CVE-2022-29083MEDIUMPrior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system coEPSS 0.4%CVE-2024-45051HIGHBypass of email address validation via encoded email addresses in DiscourseEPSS 0.4%CVE-2026-16972MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2024-2244MEDIUMREST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successfuEPSS 0.4%CVE-2026-26128HIGHWindows SMB Server Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-48780HIGHForem vulnerable to bypass of email address domain restrictionsEPSS 0.4%CVE-2026-46355HIGHBigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUserEPSS 0.4%CVE-2022-3156HIGHRockwell Automation Studio 5000 Logix Emulate Vulnerable to a Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-46607MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authEPSS 0.4%CVE-2022-43528MEDIUMUnder certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authenticaEPSS 0.4%CVE-2026-58253HIGHNATS Server: Route API Auth BypassEPSS 0.4%CVE-2025-54419CRITICALNode-SAML Contains SAML Signature Verification VulnerabilityEPSS 0.4%CVE-2022-35646MEDIUMIBM Security Verify Governance, Identity Manager security bypassEPSS 0.4%CVE-2026-0405MEDIUMAuthentication Bypass in NETGEAR Orbi DevicesEPSS 0.4%CVE-2026-55235MEDIUMlanggraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authenticationEPSS 0.4%CVE-2017-14018—An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before NoveEPSS 0.4%CVE-2026-78425HIGHSAML Audience Confusion Allows Cross-SP AuthenticationEPSS 0.4%CVE-2026-45363CRITICAL`jwt` (Ruby gem) - empty-key HMAC bypassEPSS 0.4%CVE-2026-48897HIGHJoomla! Core - [20260512] - MFA Authentication BypassEPSS 0.4%