Falhas do tipo CWE-287

2.410 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2021-4073CRITICALRegistrationMagic <= 5.0.1.7 Authentication BypassEPSS 7.0%CVE-2025-63207CRITICALThe R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentEPSS 7.0%CVE-2026-41276HIGHFlowise: AccountService resetPassword Authentication Bypass VulnerabilityEPSS 6.9%CVE-2023-37266CRITICALWeak json web token (JWT) secrets in CasaOSEPSS 6.8%CVE-2017-12337—A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could aEPSS 6.4%CVE-2020-12145MEDIUMSilver Peak Unity OrchestratorTM authentication can be subverted through manipulation of HTTP headers.EPSS 6.0%CVE-2022-39290HIGHCSRF key bypass using HTTP methods in zoneminderEPSS 6.0%CVE-2021-21513HIGHDell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configEPSS 5.9%CVE-2022-0715HIGHA CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a keEPSS 5.8%CVE-2025-10365CRITICALAuthentication Bypass in Evertz SDVNEPSS 5.6%CVE-2022-0492HIGHA vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certaEPSS 5.5%KEVCVE-2017-6747—A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypaEPSS 5.5%CVE-2021-34993CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. AuthenticationEPSS 5.4%CVE-2019-1917CRITICALCisco Vision Dynamic Signage Director REST API Authentication Bypass VulnerabilityEPSS 5.3%CVE-2019-12643CRITICALCisco REST API Container for IOS XE Software Authentication Bypass VulnerabilityEPSS 5.3%CVE-2017-12229—A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, reEPSS 5.2%CVE-2017-16748—An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and priEPSS 5.1%CVE-2018-0238—A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenEPSS 5.1%CVE-2018-10611—Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to alEPSS 5.0%CVE-2012-5864—Sinapsi eSolar Improper AuthenticationEPSS 4.9%