Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2019-18318—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2019-18317—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2019-18319—A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network accessEPSS 1.1%CVE-2024-30299CRITICALTenable Vulnerability Disclosure | API Auth BypassEPSS 1.1%CVE-2023-41264CRITICALNetwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, lEPSS 1.0%CVE-2020-16102HIGHImproper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invaEPSS 1.0%CVE-2022-45174CRITICALAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under thEPSS 1.0%CVE-2021-32794MEDIUMAccidental removal of IPCPassword (< 5.1.2.4)EPSS 1.0%CVE-2022-45173CRITICALAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskEPSS 1.0%CVE-2022-29883MEDIUMA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pagEPSS 1.0%CVE-2026-78167CRITICALEFM ipTIME T16000M Session Validation httpcon_check_session_url improper authenticationEPSS 1.0%CVE-2022-34379CRITICALDell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of theEPSS 1.0%CVE-2023-2586CRITICAL Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices EPSS 1.0%CVE-2023-31007NONEApache Pulsar: Broker does not always disconnect client when authentication data expiresEPSS 1.0%CVE-2023-27582CRITICALFull authentication bypass if SASL authorization username is specifiedEPSS 1.0%CVE-2026-12773MEDIUMBerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authenticationEPSS 1.0%CVE-2024-36264CRITICALApache Submarine Commons Utils: default secretEPSS 1.0%CVE-2022-31685CRITICALVMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to WorkspaEPSS 1.0%CVE-2022-24813MEDIUMAuthentication Bypass Using an Alternate Path or Channel in CreateWikiEPSS 1.0%CVE-2023-50275HIGHHPE OneView may allow clusterService Authentication Bypass resulting in denial of service.EPSS 1.0%