Falhas do tipo CWE-294

213 resultados

Exposição de informações sensíveis a atores não autorizados

Fraqueza na qual dados sensíveis (credenciais, chaves, PII, tokens) são acessíveis por usuários ou processos que não deveriam ter acesso. Ocorre por falhas em controle de acesso, armazenamento inadequado ou transmissão desprotegida, permitindo vazamento ou roubo dessas informações.

Exemplo

Uma aplicação grava tokens de autenticação em logs em texto plano acessíveis via endpoint público, ou armazena senhas sem hash em banco de dados com permissões leitura aberta. Um atacante consegue ler essas credenciais e impersonar usuários legítimos.

Como mitigar

Implemente controle de acesso rigoroso baseado em papéis (RBAC/ABAC), criptografe dados sensíveis em repouso e em trânsito (TLS, AES), nunca registre credenciais em logs, e revise regularmente permissões de arquivos e endpoints para garantir que apenas atores autorizados acessem informações críticas.

CVE-2017-3191D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A rEPSS 62.5%CVE-2023-49231CRITICALAn authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administraEPSS 42.9%CVE-2022-29593MEDIUMrelay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need EPSS 14.0%CVE-2022-22806A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malEPSS 12.5%CVE-2017-6034CRITICALSchneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replayEPSS 5.2%CVE-2018-7790CRITICALAn Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firEPSS 2.5%CVE-2022-43704MEDIUMThe Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requirement to communicate usEPSS 1.9%CVE-2021-38296Apache Spark Key Negotiation VulnerabilityEPSS 1.8%CVE-2018-17903SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.EPSS 1.6%CVE-2023-30909CRITICALA remote authentication bypass issue exists in some OneView APIs. EPSS 1.5%CVE-2018-17932JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, whicEPSS 1.5%CVE-2018-19025In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (FirmwareEPSS 1.5%CVE-2020-5261HIGHMissing Token Replay DetectionEPSS 1.5%CVE-2022-45789HIGHA CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the cEPSS 1.5%CVE-2018-1128It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker haviEPSS 1.4%CVE-2019-18226Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras andEPSS 1.4%CVE-2020-6972In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay atEPSS 1.3%CVE-2026-62911HIGHMicrosoft Exchange Server Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2023-2846HIGHAuthentication Bypass Vulnerability in MELSEC-F Series main moduleEPSS 1.3%CVE-2022-37011A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All veEPSS 1.2%