Falhas do tipo CWE-287

2.419 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2021-32753HIGHWeak password in API gateway in EdgeX Foundry Edinburgh, Fuji, Geneva, and Hanoi releases allows remote attackers to obtain authentication token via dictionary-based password attack when OAuth2 authentication method is enabled.EPSS 0.8%CVE-2023-23612MEDIUMIssue with whitespace in JWT roles in OpenSearchEPSS 0.8%CVE-2020-25183HIGHMedtronic MyCareLink Smart Improper AuthenticationEPSS 0.8%CVE-2026-12795MEDIUMBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationEPSS 0.8%CVE-2024-3263CRITICALImproper authentication in YMS VIS ProEPSS 0.8%CVE-2023-39196MEDIUMApache Ozone: Missing mutual TLS authentication in one of the service internal Ozone Storage Container Manager endpointsEPSS 0.8%CVE-2026-1203MEDIUMCRMEB JSON Token LoginServices.php remoteRegister improper authenticationEPSS 0.8%CVE-2026-49003CRITICALUnauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 ProductEPSS 0.8%CVE-2020-14380—An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant externEPSS 0.8%CVE-2025-15099MEDIUMsimstudioai sim CRON Secret internal.ts improper authenticationEPSS 0.8%CVE-2026-82693CRITICALTenda AC1206 Web UI telnet TendaTelnet missing authenticationEPSS 0.8%CVE-2022-32514CRITICALA CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web pEPSS 0.8%CVE-2018-17926—The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicioEPSS 0.8%CVE-2023-1464HIGHSourceCodester Medicine Tracker System improper authenticationEPSS 0.8%CVE-2024-10111HIGHOAuth Single Sign On – SSO (OAuth Client) <= 6.26.3 - Authentication BypassEPSS 0.8%CVE-2023-24093CRITICALAn access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.EPSS 0.8%CVE-2017-12213—A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches couEPSS 0.8%CVE-2023-21817HIGHWindows Kerberos Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-14714MEDIUMzhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authenticationEPSS 0.8%CVE-2023-3065CRITICALMobatime mobile application - Authentication bypassEPSS 0.8%