Fallos del tipo CWE-308

16 resultados

Autenticação de fator único

É quando um sistema protege acesso crítico usando apenas uma forma de verificação de identidade (senha, token, PIN), sem exigir um segundo fator independente. Isso deixa a conta exposta se esse fator único for comprometido — seja por força bruta, phishing, vaza de banco de dados ou mal uso de credenciais.

Ejemplo

Um portal bancário que exige apenas senha para acessar transferências, sem SMS, app de autenticação ou biometria. Se um atacante consegue a senha (por phishing ou leak), entra direto na conta sem bloqueio adicional.

Cómo mitigar

Implemente autenticação multifator (MFA) para operações sensíveis: combine senha com SMS, email, app authenticator ou biometria. Para serviços críticos, exija sempre 2+ fatores de fontes diferentes (algo que você sabe + algo que você tem ou é).

CVE-2023-49075HIGHPimcore Admin UI has Two Factor Authentication disabled for non admin security firewallsEPSS 1.4%CVE-2023-25681MEDIUMIBM Spectrum Virtualize security bypassEPSS 0.6%CVE-2026-56022MEDIUMWebmin MFA bypassEPSS 0.6%CVE-2026-67611HIGHOpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART ConfigurationEPSS 0.5%CVE-2025-42959HIGHMissing Authentication check after implementation of SAP Security Note 3007182 and 3537476EPSS 0.5%CVE-2023-50934MEDIUMIBM PowerSC improper authenticationEPSS 0.4%CVE-2024-47652HIGHInsecure Authentication VulnerabilityEPSS 0.4%CVE-2023-34228MEDIUMIn JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actionsEPSS 0.4%CVE-2026-85590HIGHphpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor DisableEPSS 0.4%CVE-2026-58240CRITICALMissing Authentication check in SAP NetWeaver (Message Server)EPSS 0.3%CVE-2025-64103HIGHZitadel Bypass Second Authentication FactorEPSS 0.3%CVE-2026-15616CRITICALLocal MFA not enforced during SSO sign-inEPSS 0.3%CVE-2026-45749HIGHTermix's TOTP two-factor authentication can be disabled or bypassed using only the account passwordEPSS 0.3%CVE-2024-27928MEDIUMVantage6: 2FA can be circumvented with hacked email accessEPSS 0.3%CVE-2024-50618MEDIUMA Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypEPSS 0.3%CVE-2026-33550LOWSOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommEPSS 0.1%