Fallos del tipo CWE-306

2613 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-8025CRITICALImproper Access Control in Dinosoft Business Solutions' Dinosoft ERPEPSS 0.5%CVE-2025-63206CRITICALAn authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing atEPSS 0.5%CVE-2024-0949CRITICALImproper Access Control in Talya Informatics' ElektrawebEPSS 0.5%CVE-2023-54350HIGHWordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedEPSS 0.5%CVE-2025-34230MEDIUMVasion Print (formerly PrinterLogic) Blind SSRF via HP log_off_single_sign_on.phpEPSS 0.5%CVE-2026-24728CRITICALInterinfo DreamMaker - Missing Authentication for Critical FunctionEPSS 0.5%CVE-2025-34229MEDIUMVasion Print (formerly PrinterLogic) Blind SSRF via HP installApp.phpEPSS 0.5%CVE-2018-25139HIGHFLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream DisclosureEPSS 0.5%CVE-2023-4857HIGH An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI caEPSS 0.5%CVE-2023-53773HIGHMiniDVBLinux 5.4 Unauthenticated Live Stream Disclosure via tv_action.shEPSS 0.5%CVE-2019-25226HIGHDongyoung Media DM-AP240T/W Unauthenticated Configuration DisclosureEPSS 0.5%CVE-2026-44327CRITICALfree5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handlerEPSS 0.5%CVE-2026-86727HIGHAVideo through 29.0 Information Disclosure via stats.json.phpEPSS 0.5%CVE-2025-34331HIGHAudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Read via download.phpEPSS 0.5%CVE-2025-40771CRITICALA vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6EPSS 0.5%CVE-2026-20781CRITICALCloudCharge cloudcharge.se Missing Authentication for Critical FunctionEPSS 0.5%CVE-2022-4240MEDIUMUnauthenticated API allowing an attacker to obtain the information about network resourcesEPSS 0.5%CVE-2026-1023HIGHGotac|Statistics Database System - Missing AuthenticationEPSS 0.5%CVE-2023-53974HIGHD-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated RequestEPSS 0.5%CVE-2023-27261MEDIUMMissing Authentication In IDAttend’s IDWeb ApplicationEPSS 0.5%