Falhas do tipo CWE-345

555 resultados

Verificação insuficiente de autenticidade de dados

A aplicação recebe dados de fontes externas (rede, arquivo, entrada do usuário) mas não valida adequadamente se eles realmente vieram de quem diz vir ou se não foram alterados no caminho. Isso permite que um atacante forje, intercepte ou modifique dados sem que o sistema detecte, comprometendo integridade e confiança.

Exemplo

Um serviço REST que confia cegamente em um campo 'user_id' vindo do cliente, sem verificar assinatura ou token, permitindo que alguém mude a URL para acessar dados de outro usuário. Ou um arquivo de configuração lido sem validar sua hash, permitindo execução de código malicioso se o arquivo for corrompido.

Como mitigar

Use mecanismos criptográficos de autenticação (HMAC, assinatura digital, certificados TLS) para garantir a origem e integridade dos dados. No lado do servidor, nunca confie em identificadores ou claims do cliente — valide contra seu próprio estado autorizado (sessão, JWT assinado, etc).

CVE-2026-18674HIGHKong Mesh multi-zone: the global control plane attributes KDS-synced resources by an unvalidated in-band zone identifierEPSS 0.4%CVE-2023-37264LOWPipelines do not validate child UIDsEPSS 0.4%CVE-2025-66255CRITICALUnauthenticated Arbitrary File Upload (upgrade_contents.php)EPSS 0.4%CVE-2024-27305MEDIUMSMTP smuggling in aiosmtpdEPSS 0.4%CVE-2022-23556HIGHCodeIgniter is vulnerable to IP address spoofing when using proxyEPSS 0.4%CVE-2018-10626MEDIUMMedtronic MyCareLink 24950 Patient Monitor Insufficient Verification of Data AuthenticityEPSS 0.4%CVE-2022-34845MEDIUMA firmware update vulnerability exists in the sysupgrade functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network packeEPSS 0.4%CVE-2022-41960MEDIUMBigBlueButton contains DoS via failed authToken validationEPSS 0.4%CVE-2019-16007MEDIUMCisco AnyConnect Secure Mobility Client for Android Service Hijack VulnerabilityEPSS 0.4%CVE-2023-41045LOWInsecure source port usage for DNS queries in GraylogEPSS 0.4%CVE-2025-63910HIGHAn authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with EPSS 0.4%CVE-2022-32252MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity chEPSS 0.4%CVE-2018-10894MEDIUMIt was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use thiEPSS 0.4%CVE-2019-3807LOWAn issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authEPSS 0.4%CVE-2023-28863CRITICALAMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.EPSS 0.4%CVE-2026-26007HIGHcryptography Subgroup Attack Due to Missing Subgroup Validation for SECT CurvesEPSS 0.3%CVE-2026-71965HIGHCyberPanel 2.4.3 Authenticated RCE via Remote Backup FeatureEPSS 0.3%CVE-2025-8980HIGHTenda G1 Firmware Update check_upload_file data authenticityEPSS 0.3%CVE-2026-9242MEDIUMRegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN RequestEPSS 0.3%CVE-2021-21588MEDIUMDell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacEPSS 0.3%