Falhas do tipo CWE-287

2.418 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2021-38412CRITICALDigi PortServer TS 16 Improper AuthenticationEPSS 1.3%CVE-2019-3798MEDIUMEscalation of Privileges in Cloud ControllerEPSS 1.3%CVE-2019-10966—In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal EPSS 1.3%CVE-2023-24830HIGHApache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorizationEPSS 1.3%CVE-2020-8200—Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active DirecEPSS 1.3%CVE-2008-3738CRITICALSession fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectorEPSS 1.3%CVE-2021-40851HIGHTCMAN GIM SQL injection vulnerabilityEPSS 1.3%CVE-2025-6763CRITICALComet System H3531 Web-based Management setupA.cfg missing authenticationEPSS 1.3%CVE-2020-2018CRITICALPAN-OS: Panorama authentication bypass vulnerabilityEPSS 1.3%CVE-2016-0796—WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and EPSS 1.3%CVE-2020-14494—OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexitEPSS 1.3%CVE-2022-2141CRITICALICSA-22-200-01 MiCODUS MV720 GPS tracker Improper AuthenticationEPSS 1.3%CVE-2020-27254—Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to impEPSS 1.3%CVE-2021-41265HIGHImproper Authentication in Flask-AppBuilderEPSS 1.3%CVE-2024-38099MEDIUMWindows Remote Desktop Licensing Service Denial of Service VulnerabilityEPSS 1.3%CVE-2018-4856—A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative accessEPSS 1.3%CVE-2019-12254CRITICALTECSON/GOK: Improper Authentication and Access Control on multiple devicesEPSS 1.3%CVE-2026-36829CRITICALAn authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validateEPSS 1.3%CVE-2024-21390HIGHMicrosoft Authenticator Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2020-14504MEDIUMThe web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attackeEPSS 1.3%