Falhas do tipo CWE-287

2.410 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2015-7755CRITICALJuniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 beforeEPSS 61.1%KEVCVE-2023-5830HIGHColumbiaSoft Document Locator WebTools login improper authenticationEPSS 60.8%CVE-2023-42442HIGHJumpServer session replays download without authenticationEPSS 58.5%CVE-2023-4415HIGHRuijie RG-EW1200G login improper authenticationEPSS 58.3%CVE-2022-24422CRITICALDell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticateEPSS 57.8%CVE-2017-7546—PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackersEPSS 56.7%CVE-2021-27651CRITICALIn versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authenticaEPSS 53.8%CVE-2024-26331HIGHReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to EPSS 51.3%CVE-2024-2862CRITICALPassword reset vulnerability without authorization on LG LED AssistantEPSS 51.0%CVE-2020-12812CRITICALAn improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to logEPSS 49.3%KEVCVE-2023-50919CRITICALAn issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. ThEPSS 47.8%CVE-2025-53778HIGHWindows NTLM Elevation of Privilege VulnerabilityEPSS 47.6%CVE-2021-22893CRITICALPulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share BrowseEPSS 47.2%KEVCVE-2024-8181CRITICALFlowise Authentication BypassEPSS 45.1%CVE-2024-3080CRITICALASUS Router - Improper AuthenticationEPSS 43.5%CVE-2023-49105CRITICALAn issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication EPSS 43.2%KEVCVE-2022-42233CRITICALTenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.EPSS 42.7%CVE-2021-37580—Apache ShenYu Admin bypass JWT authenticationEPSS 41.9%CVE-2022-25369CRITICALAn issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists dEPSS 40.0%CVE-2025-32815MEDIUMAn issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.EPSS 39.7%