Falhas do tipo CWE-287

2.415 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2017-7931—In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acceEPSS 2.5%CVE-2019-18337CRITICALA vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authEPSS 2.5%CVE-2026-11374CRITICALAccount Takeover via Predictable SSO Ticket GenerationEPSS 2.5%CVE-2024-49757HIGHZitadel User Registration Bypass VulnerabilityEPSS 2.5%CVE-2018-0121—A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could alloEPSS 2.5%CVE-2019-18315—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 2.5%CVE-2017-13995—An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does nEPSS 2.5%CVE-2025-32975CRITICALQuest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 EPSS 2.5%KEVCVE-2020-10888MEDIUMThis vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC17EPSS 2.5%CVE-2023-22964CRITICALZoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication iEPSS 2.4%CVE-2017-7420—An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer anEPSS 2.4%CVE-2017-11428HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.4%CVE-2022-48066CRITICALAn issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.EPSS 2.4%CVE-2020-3125HIGHCisco Adaptive Security Appliance Software Kerberos Authentication Bypass VulnerabilityEPSS 2.4%CVE-2017-11430HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 2.4%CVE-2018-1112HIGHglusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster clientEPSS 2.4%CVE-2021-43786CRITICALAPI token verification can be bypassedEPSS 2.4%CVE-2020-3361HIGHCisco Webex Meetings and Cisco Webex Meetings Server Token Handling Unauthorized Access VulnerabilityEPSS 2.4%CVE-2022-24883HIGHFreeRDP Server authentication might allow invalid credentials to passEPSS 2.4%CVE-2022-39205CRITICALAccess Control Bypass in OnedevEPSS 2.4%