Falhas do tipo CWE-287

2.454 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-21460MEDIUMImproper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.EPSS 0.2%CVE-2025-48909HIGHBypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentialiEPSS 0.2%CVE-2024-36266HIGHA vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authenEPSS 0.2%CVE-2024-38825MEDIUMCVE-2024-38825 Salt AdvisoryEPSS 0.2%CVE-2022-48575LOWA person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issueEPSS 0.2%CVE-2025-61679HIGHAnyquery Unauthenticated Access Vulnerability Exposes Private Integration DataEPSS 0.2%CVE-2026-15384MEDIUMManual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOREPSS 0.2%CVE-2023-21425MEDIUMImproper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive informaEPSS 0.2%CVE-2023-21437MEDIUMImproper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive informEPSS 0.2%CVE-2023-21484MEDIUMImproper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to executeEPSS 0.1%CVE-2024-24279HIGHAn issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated EPSS 0.1%CVE-2026-20885HIGHImproper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosuEPSS 0.1%CVE-2026-1568CRITICALRapid7 InsightVM Signature Validation VulnerabilityEPSS 0.1%CVE-2025-43281HIGHThe issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate theEPSS 0.1%CVE-2023-21487MEDIUMImproper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call settingEPSS 0.1%CVE-2023-41751MEDIUMSensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) bEPSS 0.1%CVE-2023-33070HIGHImproper Authentication in Automotive OSEPSS 0.1%CVE-2022-33242HIGHImproper authentication in Qualcomm IPCEPSS 0.1%CVE-2025-53169HIGHVulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this EPSS 0.1%CVE-2025-25201MEDIUMImproper Validation of Admin Key in PIV SmartcardEPSS 0.1%