Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2023-6483CRITICALImproper Authentication Vulnerability in ADiTaaS EPSS 1.2%CVE-2024-49076HIGHWindows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2019-6527—PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the passworEPSS 1.2%CVE-2026-1368HIGHVideo Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature GenerationEPSS 1.2%CVE-2021-41312HIGHAffected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service ManageEPSS 1.2%CVE-2022-46145HIGHauthentik vulnerable to unauthorized user creation and potential account takeoverEPSS 1.2%CVE-2020-24675CRITICALWeak Authentication in Symphony PlusEPSS 1.2%CVE-2023-6907MEDIUMcodelyfe Stupid Simple CMS Deletion Interface delete.php improper authenticationEPSS 1.2%CVE-2021-43444HIGHONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak EPSS 1.2%CVE-2022-46146MEDIUMPrometheus Exporter Toolkit vulnerable to basic authentication bypassEPSS 1.2%CVE-2021-22796—A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected PEPSS 1.2%CVE-2020-15243CRITICALWebApi Authentication attribute missing in SmartstoreEPSS 1.2%CVE-2022-2133—OAuth Single Sign On < 6.22.6 - Authentication BypassEPSS 1.2%CVE-2017-9630—An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, EPSS 1.2%CVE-2019-18322—A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.2%CVE-2019-18321—A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 ServEPSS 1.2%CVE-2024-38124CRITICALWindows Netlogon Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2024-40794MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6.EPSS 1.2%CVE-2023-52160MEDIUMThe implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be confEPSS 1.2%CVE-2025-49831CRITICALConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenticator Bypass via Mis-configured Network DeviceEPSS 1.2%