Fallos del tipo CWE-778

26 resultados

Registro de eventos insuficiente

A aplicação não registra adequadamente eventos de segurança relevantes (autenticação, autorização, operações críticas, erros), dificultando detecção de ataques, investigação forense e conformidade. Sem logs suficientes, você não consegue saber o que aconteceu na sua aplicação quando algo dá errado.

Ejemplo

Um sistema aceita múltiplas tentativas de login falhadas sem registrá-las; quando uma conta é comprometida, não há rastro de quando ou como o atacante entrou. Ou uma API crítica altera dados de usuários sem registrar quem fez, quando e o quê foi alterado.

Cómo mitigar

Implemente logs estruturados (JSON, formato padronizado) de eventos de segurança: tentativas de autenticação, mudanças de autorização, operações em dados sensíveis, erros de validação. Garanta que os logs sejam armazenados com integridade (imutáveis ou em destino seguro) e revisados periodicamente. Use níveis de severidade (INFO, WARNING, ERROR) para filtrar o relevante.

CVE-2019-7613Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entryEPSS 1.3%CVE-2019-19277A vulnerability has been identified in SIPORT MP (All versions < 3.1.4). Vulnerable versions of the device allow the creation of special accEPSS 1.2%CVE-2019-19295MEDIUMA vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) does not enforceEPSS 1.1%CVE-2022-31120LOWFederated share accepting/declining is not logged in audit log in Nextcloud ServerEPSS 0.8%CVE-2021-43419HIGHAn Information Disclosure vulnerability exists in Opay Mobile application 1.5.1.26 and maybe be higher in the logcat app.EPSS 0.7%CVE-2022-30305LOWAn insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptorEPSS 0.6%CVE-2024-48967CRITICALLife2000 ventilator and Service PC lack sufficient audit logging capabilitiesEPSS 0.6%CVE-2022-25783MEDIUMHacking attempts from logged-in users are not properly logged by GMEPSS 0.6%CVE-2021-33689LOWWhen user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version EPSS 0.5%CVE-2024-10863MEDIUMClient-side audit exclusion vulnerabilityEPSS 0.4%CVE-2025-2562MEDIUMInsufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a storedEPSS 0.4%CVE-2024-2291MEDIUMMOVEit Transfer Logging Bypass VulnerabilityEPSS 0.4%CVE-2026-41709LOWESX insufficient logging vulnerabilityEPSS 0.4%CVE-2023-1995MEDIUMInsufficient Logging Vulnerability in HiRDBEPSS 0.4%CVE-2021-32680LOWAudit log is not properly logging unsetting of share expiration dateEPSS 0.4%CVE-2026-25598MEDIUMBypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)EPSS 0.3%CVE-2025-66552MEDIUMNextcloud Server admin_audit does not log all actions on files in groupfoldersEPSS 0.3%CVE-2026-32693HIGHUnauthorized access to Kubernetes secrets in JujuEPSS 0.3%CVE-2026-3494MEDIUMMariaDB Server Audit Plugin Comment Handling BypassEPSS 0.3%CVE-2025-53498MEDIUMLack of Audit Logging in AbuseFilterEPSS 0.2%