Falhas do tipo CWE-308

16 resultados

Autenticação com único fator

Ocorre quando um sistema depende de apenas uma forma de validação da identidade do usuário (tipicamente senha), sem exigir uma segunda camada de verificação. Isso deixa a conta vulnerável se a credencial for comprometida, pois não há barreira adicional para bloquear acesso não autorizado.

Exemplo

Um banco online que só pede CPF e senha no login. Se um atacante rouba a senha via phishing ou vazamento de dados, consegue acessar a conta imediatamente sem qualquer outra verificação (SMS, token, biometria).

Como mitigar

Implemente autenticação multifator (MFA): exija um segundo fator obrigatório após a senha, como código SMS, app de autenticação (TOTP), chave de segurança ou biometria. Para sistemas críticos, considere MFA adaptativo que se ativa conforme o risco detectado.

CVE-2023-49075HIGHPimcore Admin UI has Two Factor Authentication disabled for non admin security firewallsEPSS 1.4%CVE-2023-25681MEDIUMIBM Spectrum Virtualize security bypassEPSS 0.6%CVE-2026-56022MEDIUMWebmin MFA bypassEPSS 0.6%CVE-2026-67611HIGHOpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART ConfigurationEPSS 0.5%CVE-2025-42959HIGHMissing Authentication check after implementation of SAP Security Note 3007182 and 3537476EPSS 0.5%CVE-2023-50934MEDIUMIBM PowerSC improper authenticationEPSS 0.4%CVE-2024-47652HIGHInsecure Authentication VulnerabilityEPSS 0.4%CVE-2023-34228MEDIUMIn JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actionsEPSS 0.4%CVE-2026-85590HIGHphpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor DisableEPSS 0.4%CVE-2026-58240CRITICALMissing Authentication check in SAP NetWeaver (Message Server)EPSS 0.3%CVE-2025-64103HIGHZitadel Bypass Second Authentication FactorEPSS 0.3%CVE-2026-15616CRITICALLocal MFA not enforced during SSO sign-inEPSS 0.3%CVE-2026-45749HIGHTermix's TOTP two-factor authentication can be disabled or bypassed using only the account passwordEPSS 0.3%CVE-2024-27928MEDIUMVantage6: 2FA can be circumvented with hacked email accessEPSS 0.3%CVE-2024-50618MEDIUMA Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypEPSS 0.3%CVE-2026-33550LOWSOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommEPSS 0.1%