Falhas do tipo CWE-306

2.593 resultados

Falta de autenticação em funcionalidades críticas

O software não valida a identidade do usuário antes de executar operações sensíveis ou que consomem recursos significativos (processamento, armazenamento, banda). Qualquer pessoa, autenticada ou não, consegue acessar e usar essas funcionalidades, criando risco de abuso, consumo não autorizado de recursos ou acesso a dados protegidos.

Exemplo

Uma API de relatórios que permite gerar análises pesadas sem verificar credenciais, permitindo um atacante disparar gerações de relatório em loop para derrubar o servidor. Ou um endpoint de backup que qualquer pessoa consegue chamar sem login, expondo dados sensíveis.

Como mitigar

Implemente verificação obrigatória de identidade (autenticação) em toda funcionalidade sensível ou cara computacionalmente. Use controles de sessão, tokens JWT ou OAuth, e combine com autorização (verificar se o usuário autenticado tem permissão específica para aquela ação).

CVE-2019-6820HIGHA CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IPEPSS 1.3%CVE-2019-13525In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to EPSS 1.3%CVE-2020-12505HIGHWAGO: Vulnerability in web-based authentication in WAGO 750-8XX Version <= FW07EPSS 1.2%CVE-2020-10038A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attackEPSS 1.2%CVE-2022-39426HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PriorEPSS 1.2%CVE-2026-27182HIGHSaturn Remote Mouse Server UDP Command Injection RCEEPSS 1.2%CVE-2024-43488HIGHVisual Studio Code extension for Arduino Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-8320MEDIUMMissing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attaEPSS 1.2%CVE-2019-6533Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway vEPSS 1.2%CVE-2025-34223CRITICALVasion Print (formerly PrinterLogic) Insecure Installation CredentialsEPSS 1.2%CVE-2019-16003MEDIUMCisco UCS Director Information Disclosure VulnerabilityEPSS 1.2%CVE-2019-15282MEDIUMCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 1.2%CVE-2024-5749HIGHCertain HP DesignJet products – Credential reflectionEPSS 1.2%CVE-2020-3461MEDIUMCisco Data Center Network Manager Information Disclosure VulnerabilityEPSS 1.2%CVE-2026-33231HIGHNLTK has unauthenticated remote shutdown in nltk.app.wordnet_appEPSS 1.2%CVE-2022-32251HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification foEPSS 1.2%CVE-2021-41104HIGHweb_server allows OTA update without checking user defined basic auth username & passwordEPSS 1.2%CVE-2024-23618CRITICALArris SURFboard SBG6950AC2 Arbitrary Code Execution VulnerabilityEPSS 1.2%CVE-2025-59090CRITICALUnauthenticated SOAP API in dormakaba Kaba exos 9300EPSS 1.2%CVE-2022-26026HIGHA denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.EPSS 1.2%