Falhas do tipo CWE-287

2.410 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2017-15135—It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly EPSS 3.8%CVE-2017-2628—curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it didEPSS 3.8%CVE-2002-2438—TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded byEPSS 3.7%CVE-2021-20020—A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.EPSS 3.7%CVE-2021-26638HIGHXi Smarthome wallpad authentication bypass vulnerabilityEPSS 3.7%CVE-2021-36306HIGHNetworking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability. A remote unautheEPSS 3.7%CVE-2022-47003CRITICALA vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web requestEPSS 3.6%CVE-2021-37624HIGHFreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofingEPSS 3.6%CVE-2018-0321—A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote MeEPSS 3.6%CVE-2022-0730—Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.EPSS 3.5%CVE-2021-24148—MStore API < 3.2.0 - Authentication Bypass With Sign In With AppleEPSS 3.4%CVE-2019-16028CRITICALCisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass VulnerabilityEPSS 3.4%CVE-2014-0760—Festo CECX-X-(C1/M1) Controller Improper AuthenticationEPSS 3.3%CVE-2017-7562MEDIUMAn authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A EPSS 3.3%CVE-2025-66039CRITICALFreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth HeaderEPSS 3.3%CVE-2022-30995CRITICALSensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, LinEPSS 3.3%CVE-2023-0905HIGHSourceCodester Employee Task Management System changePasswordForEmployee.php improper authenticationEPSS 3.2%CVE-2017-12236—A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthentEPSS 3.1%CVE-2026-59208HIGHn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity ResolutionEPSS 3.1%CVE-2023-30869CRITICALWordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege EscalationEPSS 3.1%