Falhas do tipo CWE-287

2.410 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2021-1571HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 9.7%CVE-2025-9533MEDIUMTOTOLINK T10 formLoginAuth.htm improper authenticationEPSS 9.4%CVE-2021-1543HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 9.3%CVE-2012-6440MEDIUMRockwell Automation ControlLogix PLC Improper Input ValidationEPSS 9.3%CVE-2016-2125MEDIUMIt was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A servEPSS 9.2%CVE-2025-44005CRITICALAn attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain pEPSS 9.1%CVE-2021-1541HIGHCisco Small Business 220 Series Smart Switches VulnerabilitiesEPSS 8.8%CVE-2018-10682CRITICALAn issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without EPSS 8.3%CVE-2021-39165HIGHUnauthenticated SQL InjectionEPSS 8.2%CVE-2025-59934CRITICALFormbricks missing JWT signature verificationEPSS 8.1%CVE-2012-6437CRITICALRockwell Automation ControlLogix PLC Improper AuthenticationEPSS 7.8%CVE-2018-14826—Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with EPSS 7.7%CVE-2025-53786HIGHMicrosoft Exchange Server Hybrid Deployment Elevation of Privilege VulnerabilityEPSS 7.7%CVE-2026-82329CRITICALPotential authentication bypass leading to administrative access in ArtifactoryEPSS 7.7%KEVCVE-2021-24527—Profile Builder < 3.4.9 - Admin Access via Password ResetEPSS 7.6%CVE-2018-7532—Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IPEPSS 7.6%CVE-2024-5805CRITICALMOVEit Gateway Authentication Bypass VulnerabilityEPSS 7.6%CVE-2025-4755MEDIUMD-Link DI-7003GV2 netconfig.asp sub_497DE4 improper authenticationEPSS 7.3%CVE-2025-46631MEDIUMImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable tEPSS 7.2%CVE-2021-42949CRITICALThe component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackEPSS 7.1%