Falhas do tipo CWE-603

22 resultados

Autenticação no lado do cliente

É quando a aplicação valida credenciais ou permissões apenas no navegador ou cliente, sem verificação correspondente no servidor. Um atacante pode contornar essas validações (modificar JavaScript, requisições HTTP ou dados locais) porque o servidor não reforça a autenticação, confiando cegamente no cliente.

Exemplo

Uma página web que oculta um botão 'Admin' via CSS ou JavaScript se o usuário não estiver logado como admin. Um atacante inspeciona o código, remove o `display: none`, clica no botão e faz requisições diretas para endpoints administrativos — que o servidor aceita porque nunca verificou se a sessão é realmente de um admin.

Como mitigar

Valide TODA autenticação e autorização no servidor: verifique tokens/sessões, papéis de usuário e permissões antes de executar qualquer ação sensível. Nunca confie em validações do cliente; use-as apenas para UX. Aplique controle de acesso no backend de forma consistente em todas as rotas e operações.

CVE-2022-3218Necta WiFi Mouse (Mouse Server) client-side authentication bypassEPSS 73.5%CVE-2020-6988HIGHRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versionsEPSS 4.0%CVE-2017-7909A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interEPSS 2.6%CVE-2020-7591A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attaEPSS 1.5%CVE-2022-33139A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCEPSS 1.2%CVE-2021-43355HIGHFresenius Kabi Agilia Connect Infusion System use of client side authenticationEPSS 1.0%CVE-2025-24517HIGHUse of client-side authentication issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a remote attaEPSS 0.8%CVE-2020-27266In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDanEPSS 0.6%CVE-2024-39375CRITICALUse of Client-Side Authentication in TELSAT marKoni FM TransmitterEPSS 0.6%CVE-2026-1363CRITICALJNC|IAQS and I6 - Client-Side Enforcement of Server-Side SecurityEPSS 0.5%CVE-2025-12868CRITICALCyberTutor|New Site Server - Use of Client-Side AuthenticationEPSS 0.5%CVE-2025-62649MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipEPSS 0.5%CVE-2025-62650HIGHThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostEPSS 0.5%CVE-2024-52327MEDIUMECOVACS lawnmower and vacuum cloud service live video PIN bypassEPSS 0.5%CVE-2024-28627HIGHAn issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.EPSS 0.4%CVE-2024-45785HIGHMUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sEPSS 0.4%CVE-2025-64119CRITICALNuvation Energy BMS Client-side AuthenticationEPSS 0.4%CVE-2026-42098HIGHAuthorization Bypass in Sparx Enterprise ArchitectEPSS 0.4%CVE-2026-8830MEDIUMKeycloak: org.keycloak/keycloak-services: keycloak: policy bypass during webauthn credential registration via client-side javascript manipulationEPSS 0.4%CVE-2025-61940HIGHMirion Medical EC2 Software NMIS BioDose Use of Client-Side AuthenticationEPSS 0.3%