Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2018-0247—A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco EPSS 0.9%CVE-2023-0311MEDIUMImproper Authentication in thorsten/phpmyfaqEPSS 0.9%CVE-2023-40660MEDIUMOpensc: potential pin bypass when card tracks its own login stateEPSS 0.9%CVE-2021-37172—A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate agEPSS 0.9%CVE-2024-6057CRITICALImproper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that EPSS 0.9%CVE-2025-2339MEDIUMotale Tale Blog logs improper authenticationEPSS 0.9%CVE-2022-2662CRITICALSequi PortBloque S Improper AuthenticationEPSS 0.9%CVE-2021-26073HIGHBroken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js pacEPSS 0.9%CVE-2023-20214CRITICALA vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, rEPSS 0.9%CVE-2022-36960HIGHSolarWinds Platform Improper Input ValidationEPSS 0.9%CVE-2023-34388MEDIUMImproper authentication could lead to session hijackingEPSS 0.9%CVE-2021-44056HIGHImproper authentication in Video StationEPSS 0.9%CVE-2021-44057HIGHImproper authentication in Photo StationEPSS 0.9%CVE-2024-46434HIGHTenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gainEPSS 0.9%CVE-2023-5970—Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external dEPSS 0.9%CVE-2024-34103HIGHCustomer account takeover via web API call & subsequent password resetEPSS 0.9%CVE-2024-39340HIGHThe authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enablEPSS 0.9%CVE-2025-2771MEDIUMBEC Technologies Multiple Routers Authentication Bypass VulnerabilityEPSS 0.9%CVE-2026-32173HIGHAzure SRE Agent Information Disclosure VulnerabilityEPSS 0.9%CVE-2022-39229MEDIUMGrafana users with email as a username can block other users from signing inEPSS 0.9%