Falhas do tipo CWE-287

2.455 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2025-10684MEDIUMConstruction Light < 1.6.8 - Subscriber+ Arbitrary Plugin ActivationEPSS 0.1%CVE-2022-25832MEDIUMImproper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app withouEPSS 0.1%CVE-2021-25347MEDIUMHijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the providerEPSS 0.1%CVE-2026-20655MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOEPSS 0.1%CVE-2024-40653HIGHIn multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a loEPSS 0.1%CVE-2023-2626HIGHAuthentication Bypass in OpenThread Boarder Router devicesEPSS 0.1%CVE-2021-25389LOWImproper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.EPSS 0.1%CVE-2022-25816MEDIUMImproper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable withoEPSS 0.1%CVE-2022-25833LOWImproper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permiEPSS 0.1%CVE-2021-25484MEDIUMImproper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.EPSS 0.1%CVE-2024-42038HIGHVulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect serviceEPSS 0.1%CVE-2018-11952HIGHImproper Authentication in TrustZoneEPSS 0.1%CVE-2022-25817MEDIUMImproper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.EPSS 0.1%CVE-2022-30755HIGHImproper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijaEPSS 0.1%CVE-2026-78236HIGHInsecure PIN derivation mechanism in Admin By Request (ABR)EPSS 0.1%CVE-2016-10394CRITICALImproper Authentication in CoreEPSS 0.1%CVE-2022-33689MEDIUMImproper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unEPSS 0.1%CVE-2026-56792MEDIUMDell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker withEPSS 0.1%CVE-2026-81473HIGHDell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker withEPSS 0.1%CVE-2022-33732MEDIUMImproper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PCEPSS 0.1%