Falhas do tipo CWE-287

2.412 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2021-34865HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. AuthentEPSS 3.1%CVE-2018-14786—Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.EPSS 3.1%CVE-2020-3297HIGHCisco Small Business Smart and Managed Switches Session Management VulnerabilityEPSS 3.0%CVE-2021-25036—All In One SEO < 4.1.5.3 - Authenticated Privilege EscalationEPSS 3.0%CVE-2025-1104MEDIUMD-Link DHP-W310AV authentication spoofingEPSS 3.0%CVE-2020-8206—An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bEPSS 3.0%CVE-2017-14008—GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.EPSS 3.0%CVE-2017-6869—A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remEPSS 3.0%CVE-2025-30287HIGHColdFusion | Improper Authentication (CWE-287)EPSS 2.9%CVE-2022-24882CRITICALServer side NTLM does not properly check parameters in FreeRDPEPSS 2.8%CVE-2017-11429HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.7%CVE-2020-10918HIGHThis vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch EPSS 2.7%CVE-2023-46290HIGHRockwell Automation FactoryTalk Services Platform Elevated Privileges VulnerabilityEPSS 2.7%CVE-2017-7920—An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for ReEPSS 2.7%CVE-2022-40664CRITICALAuthentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcherEPSS 2.7%CVE-2018-13804—A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UAEPSS 2.7%CVE-2018-5459—An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute dEPSS 2.7%CVE-2018-5451—In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficienEPSS 2.6%CVE-2018-0271—A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker toEPSS 2.6%CVE-2017-7919—An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific EPSS 2.6%