Falhas do tipo CWE-1390

95 resultados

Autenticação fraca

Fraqueza em que o mecanismo de autenticação não valida suficientemente a identidade do usuário, aceitando credenciais insuficientes, previsíveis ou sem proteção adequada. Um atacante consegue contornar a autenticação com pouco esforço, obtendo acesso não autorizado ao sistema.

Exemplo

Um app que permite login apenas com username (sem senha), ou um serviço que usa tokens de autenticação hardcoded que nunca expiram, ou ainda uma API que valida acesso só verificando se um campo numérico simples está presente na requisição.

Como mitigar

Implemente autenticação multifatorial, use hashing forte para senhas (bcrypt, Argon2), enforce expiração de tokens, valide credenciais contra armazenamento seguro sem padrões previsíveis, e aplique rate limiting em tentativas de login. Considere OAuth 2.0 ou SAML para delegação segura.

CVE-2025-57713LOWFile Station 5EPSS 0.5%CVE-2026-73819CRITICALEbyte NA111-M Weak AuthenticationEPSS 0.5%CVE-2026-77483HIGHSQL Server Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2024-29837HIGHPoor session management in Evolution Controller allows administrator functionality for unauthenticated connectionsEPSS 0.5%CVE-2024-45367CRITICALOptigo Networks ONS-S8 Spectra Aggregation Switch Weak AuthenticationEPSS 0.5%CVE-2026-50756HIGHAn issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider componentEPSS 0.5%CVE-2025-50173HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-4094MEDIUMWeak authentication vulnerability in Fujitsu Arconte ÁureaEPSS 0.5%CVE-2025-63807CRITICALAn issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak EPSS 0.5%CVE-2022-45860MEDIUMA weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versEPSS 0.5%CVE-2024-48886HIGHA weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, ForEPSS 0.5%CVE-2026-6274CRITICALAuthentication Bypass in DTS Electronics' Redline WR3200EPSS 0.5%CVE-2025-5484HIGHSinoTrack GPS Receiver Weak AuthenticationEPSS 0.5%CVE-2026-6886CRITICALBorG Technology Corporation|Borg SPM 2007 - Authentication BypassEPSS 0.5%CVE-2024-39848CRITICALInternet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.midEPSS 0.4%CVE-2026-59554HIGHWordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerabilityEPSS 0.4%CVE-2026-0204HIGHA vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific EPSS 0.4%CVE-2025-21552MEDIUMVulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). SupporteEPSS 0.4%CVE-2026-28710HIGHSensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber ProtectEPSS 0.4%CVE-2025-29994HIGHImproper Authentication Vulnerability in CAP back office applicationEPSS 0.4%