Falhas do tipo CWE-640

218 resultados

Mecanismo fraco de recuperação de senha

A aplicação oferece um fluxo de recuperação de senha (esqueci minha senha) que é facilmente contornável ou previsível. Um atacante pode adivinhar perguntas de segurança, interceptar links de reset, reusar tokens, ou explorar validações fracas para assumir contas alheias sem conhecer a senha original.

Exemplo

Um site envia um link de reset de senha por e-mail, mas o token nunca expira e é simplesmente o ID do usuário codificado em base64. Um atacante pode reutilizar tokens antigos ou gerar novos para qualquer usuário, resetando suas senhas à vontade.

Como mitigar

Implemente tokens de reset com alta entropia, validade curta (15-30 min), uso único, e vinculação ao IP/sessão. Valide a identidade antes do reset (OTP, e-mail de confirmação, desafio adaptativo). Registre e monitore tentativas anormais de recuperação.

CVE-2023-4448MEDIUMOpenRapid RapidCMS run-movepass.php password recoveryEPSS 0.7%CVE-2026-25858CRITICALmacrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP DisclosureEPSS 0.6%CVE-2025-10127HIGHDaikin Europe N.V Security Gateway Weak Password Recovery Mechanism for Forgotten PasswordEPSS 0.6%CVE-2023-7264HIGHBuild App Online <= 1.0.22 - Account Takeover via Weak Password Reset MechanismEPSS 0.6%CVE-2022-47697CRITICALCOMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeovEPSS 0.6%CVE-2026-11551CRITICALBranda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account TakeoverEPSS 0.6%CVE-2023-35717HIGHTP-Link Tapo C210 Password Recovery Authentication Bypass VulnerabilityEPSS 0.6%CVE-2024-9302HIGHApp Builder – Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTPEPSS 0.6%CVE-2026-15689CRITICALDancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_sendEPSS 0.6%CVE-2024-0186LOWHuiRan Host Reseller System HTTP POST Request password recoveryEPSS 0.6%CVE-2021-27654HIGHForgotten password reset functionality for local accounts can be used to bypass local authentication checks.EPSS 0.6%CVE-2023-47107HIGHPILOS account takeover through password reset poisoningEPSS 0.6%CVE-2024-2463HIGHWeak password recovery mechanism in CDeXEPSS 0.6%CVE-2024-0491MEDIUMHuaxia ERP UserController.java password recoveryEPSS 0.6%CVE-2026-7459HIGHSimple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Event Reaction EndpointEPSS 0.6%CVE-2025-64113CRITICALEmby Server allows attackers to gain administrative server access without preconditionsEPSS 0.6%CVE-2015-10071LOWgitter-badger ezpublish-modern-legacy forgotpassword.php password recoveryEPSS 0.6%CVE-2026-1325MEDIUMSangfor Operation and Maintenance Security Management System edit_pwd_mall password recoveryEPSS 0.6%CVE-2026-56081CRITICALCap-go - Account Lockout via 2FA Misconfiguration on Unverified EmailEPSS 0.6%CVE-2026-77264CRITICALAutomation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token DisclosureEPSS 0.6%