Falhas do tipo CWE-287

2.453 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-20924MEDIUMIn (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of prEPSS 0.2%CVE-2026-45153MEDIUMNextcloud: PIN bypass in PassCodeActivity via back buttonEPSS 0.2%CVE-2022-22283LOWImproper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.EPSS 0.2%CVE-2025-25451MEDIUMAn issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the "2fa_autEPSS 0.2%CVE-2026-43766MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOSEPSS 0.2%CVE-2026-78560MEDIUMImproper Authentication Validation in Okta Access Gateway Pass-Through Authentication SourceEPSS 0.2%CVE-2026-53514HIGHBetter Auth: Unauthorized invitation acceptance via unverified email match in organization pluginEPSS 0.2%CVE-2022-34380CRITICALDell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privEPSS 0.2%CVE-2026-12586HIGHLenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password ResetEPSS 0.2%CVE-2025-68931HIGHJervis has AES CBC Mode Without AuthenticationEPSS 0.2%CVE-2025-46590MEDIUMBypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypasEPSS 0.2%CVE-2023-0209HIGHNVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA is missing, which mayEPSS 0.2%CVE-2023-32661MEDIUMImproper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version EPSS 0.2%CVE-2022-47974MEDIUMThe Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the BlueEPSS 0.2%CVE-2023-2638MEDIUMRockwell Automation FactoryTalk System Services Vulnerable to a Denial-of-Service AttackEPSS 0.2%CVE-2022-48314MEDIUMThe Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerabEPSS 0.2%CVE-2021-25506MEDIUMNon-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial oEPSS 0.2%CVE-2022-21794HIGHImproper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits befEPSS 0.2%CVE-2026-49852HIGHjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)EPSS 0.2%CVE-2026-47838MEDIUMUnauthorized User Impersonation when Using X.509 Client CertificatesEPSS 0.2%