Falhas do tipo CWE-287

2.418 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2020-36533LOWKlapp App JSON Web Token improper authenticationEPSS 1.5%CVE-2023-29463HIGHPavilion8 Security Misconfiguration VulnerabilityEPSS 1.5%CVE-2020-8272—Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8EPSS 1.5%CVE-2022-39042CRITICALaEnrich a+HRD - Improper AuthenticationEPSS 1.5%CVE-2026-44551CRITICALOpen WebUI: LDAP Empty Password Authentication BypassEPSS 1.5%CVE-2021-21329HIGHMulti Factor Authentication Token Improperly Validated On User LoginEPSS 1.5%CVE-2019-6832—A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formeEPSS 1.5%CVE-2019-1724HIGHCisco Small Business RV320 and RV325 Routers Session Hijacking VulnerabilityEPSS 1.5%CVE-2023-47504MEDIUMWordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerabilityEPSS 1.5%CVE-2025-1723HIGHAccount takeoverEPSS 1.4%CVE-2021-23847CRITICALUnauthenticated Information Extraction VulnerabilityEPSS 1.4%CVE-2022-31013CRITICALAuthentication bypass in Vartalap chat-serverEPSS 1.4%CVE-2019-1946MEDIUMCisco Enterprise NFV Infrastructure Software Web-Based Management Interface Authentication Bypass VulnerabilityEPSS 1.4%CVE-2022-43504MEDIUMImproper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email addrEPSS 1.4%CVE-2023-41999CRITICALArcserve UDP Management Authentication Bypass EPSS 1.4%CVE-2022-37913CRITICALVulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.4%CVE-2022-37914CRITICALVulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.4%CVE-2023-34340CRITICALApache Accumulo: Accumulo 2.1.0 may incorrectly validate cached credentialsEPSS 1.4%CVE-2021-39177HIGHUser impersonation due to incorrect handling of the login JWTEPSS 1.4%CVE-2019-19104CRITICALABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access ControlEPSS 1.4%