Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2020-15164CRITICALAuthentication Bypass in Scratch Login (mediawiki-scratch-login)EPSS 1.2%CVE-2024-23470CRITICALSolarWinds Access Rights Manager (ARM) UserScriptHumster Exposed Dangerous Method Remote Command Execution VulnerabilityEPSS 1.2%CVE-2022-38744HIGHFactoryTalk Alarm and Events Server Vulnerable to Denial-Of-Service AttackEPSS 1.2%CVE-2018-25043MEDIUMuTorrent PRNG improper authenticationEPSS 1.2%CVE-2026-22594HIGHGhost has Staff 2FA bypassEPSS 1.1%CVE-2025-21349MEDIUMWindows Remote Desktop Configuration Service Tampering VulnerabilityEPSS 1.1%CVE-2022-34839MEDIUMWordPress WP OAuth2 Server plugin <= 1.0.1 - Authentication Bypass vulnerabilityEPSS 1.1%CVE-2022-24857HIGHMulti factor authentication bypass in django-mfa3EPSS 1.1%CVE-2025-30430CRITICALThis issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.EPSS 1.1%CVE-2024-51767HIGHAn authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.EPSS 1.1%CVE-2020-3410HIGHCisco Firepower Management Center Software Common Access Card Authentication Bypass VulnerabilityEPSS 1.1%CVE-2021-3632—A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already rEPSS 1.1%CVE-2023-6342MEDIUMTyler Technologies Court Case Management Plus "pay for print" allows authentication bypassEPSS 1.1%CVE-2023-1778CRITICALDefault Credential Vulnerability in GajShield Data Security FirewallEPSS 1.1%CVE-2023-25601—Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authenticationEPSS 1.1%CVE-2020-10916HIGHThis vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 85EPSS 1.1%CVE-2024-34340CRITICALAuthentication Bypass when using using older password hashesEPSS 1.1%CVE-2023-44302HIGH Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploiEPSS 1.1%CVE-2021-3046MEDIUMPAN-OS: Improper SAML Authentication Vulnerability in GlobalProtect PortalEPSS 1.1%CVE-2019-18906CRITICALcryptctl: client side password hashing is equivalent to clear text password storageEPSS 1.1%