Fallos del tipo CWE-305

168 resultados

Bypass de autenticação por fraqueza secundária

A autenticação em si é criptograficamente correta, mas pode ser contornada por outra vulnerabilidade no código ou na lógica da aplicação. Exemplo: validar corretamente a senha, mas aceitar um token expirado, ou checar credenciais mas não validar a origem da requisição. O risco é que o atacante não quebra o algoritmo — ele encontra uma porta dos fundos.

Ejemplo

Sistema que valida login com hash bcrypt impecável, mas depois aceita qualquer usuário se um parâmetro GET 'admin=true' estiver presente. Ou API que verifica JWT corretamente, mas esquece de validar se a sessão foi revogada no servidor.

Cómo mitigar

Revise toda a lógica de fluxo após a autenticação: não confie apenas no algoritmo criptográfico. Valide o contexto (origem, timestamp, revogação), execute testes de penetração focados em bypass (parâmetros extras, header manipulation, race conditions) e implemente lista de controle de acesso (ACL) robusta em cada endpoint sensível.

CVE-2023-34137SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authenticatioEPSS 1.0%CVE-2022-0451MEDIUMAuth bypass in Dark SDKEPSS 1.0%CVE-2024-7557HIGHOdh-dashboard: odh-model-controller: cross-model authentication bypass in openshift aiEPSS 0.9%CVE-2020-14359A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass oEPSS 0.9%CVE-2025-46801CRITICALPgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerabilEPSS 0.9%CVE-2023-20154CRITICALCisco Modeling Labs External Authentication Bypass VulnerabilityEPSS 0.9%CVE-2024-1202CRITICALAuthentication Bypass in XPodas' OctopodEPSS 0.9%CVE-2024-3847CRITICALInsufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policyEPSS 0.9%CVE-2024-20378HIGHA vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieveEPSS 0.8%CVE-2021-45031HIGHWeak Authentication in Login Function of USC+EPSS 0.8%CVE-2025-24522CRITICALKUNBUS Revolution Pi Authentication Bypass by Primary WeaknessEPSS 0.8%CVE-2023-1833CRITICALAuthentication Bypass in Redline RouterEPSS 0.8%CVE-2023-4501CRITICALAuthentication bypass in OpenText (Micro Focus) Enterprise ServerEPSS 0.8%CVE-2021-28503HIGHIn Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.EPSS 0.7%CVE-2026-86207HIGHAuthentication bypass leads to unauthorised access to N-centralEPSS 0.7%CVE-2026-22153HIGHAn Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauEPSS 0.7%CVE-2023-6153CRITICALAuthentication Bypass in TeoSOFT Software TeoBASEEPSS 0.7%CVE-2025-56132HIGHLiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distiEPSS 0.7%CVE-2023-4898HIGHAuthentication Bypass by Primary Weakness in mintplex-labs/anything-llmEPSS 0.7%CVE-2023-4727HIGHCa: token authentication bypass vulnerabilityEPSS 0.7%