Weaknesses of type CWE-264

288 results

Controle de acesso e privilégios inadequado

A fraqueza ocorre quando a aplicação não valida corretamente quem pode fazer o quê, permitindo que usuários acessem recursos ou executem operações acima de seus privilégios. Isso acontece porque as verificações de autorização são ausentes, incompletas ou contornáveis, expondo dados sensíveis ou permitindo ações não autorizadas.

Example

Um usuário comum consegue listar ou modificar dados de outros usuários alterando um ID na URL (ex: /profile/123 → /profile/999) sem que o servidor valide se ele tem permissão para acessar aquele perfil. Ou um atacante executa ações administrativas porque a aplicação só verifica autenticação, não autorização.

How to mitigate

Implemente verificações de autorização em toda operação sensível: valide não apenas se o usuário está logado, mas se ele tem permissão específica para aquele recurso. Use listas de controle de acesso (ACL), roles bem definidas e princípio do menor privilégio. Teste sistematicamente tentativas de escalação e acesso lateral entre usuários.

CVE-2019-1620CRITICALCisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution VulnerabilityEPSS 83.8%CVE-2017-6622A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass auEPSS 62.2%CVE-2020-12028HIGHRockwell Automation FactoryTalk View SEEPSS 53.0%CVE-2019-1621HIGHCisco Data Center Network Manager Arbitrary File Download VulnerabilityEPSS 29.8%CVE-2017-6640A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the EPSS 10.7%CVE-2017-6635A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticatedEPSS 9.7%CVE-2019-1978MEDIUMCisco Firepower Threat Defense Software Stream Reassembly Bypass VulnerabilityEPSS 9.4%CVE-2017-6637A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticatedEPSS 7.8%CVE-2019-1723CRITICALCisco Common Services Platform Collector Static Credential VulnerabilityEPSS 5.8%CVE-2020-3229HIGHCisco IOS XE Software Web UI Privilege Escalation VulnerabilityEPSS 5.3%CVE-2017-3831A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to EPSS 5.3%CVE-2018-0293A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI coEPSS 4.8%CVE-2018-5472Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to EPSS 4.6%CVE-2018-5468Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unaEPSS 4.6%CVE-2020-7352HIGHGOG Galaxy GalaxyClientService Privilege EscalationEPSS 3.8%CVE-2018-11462A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versEPSS 3.7%CVE-2021-33036Apache Hadoop Privilege escalation vulnerabilityEPSS 3.6%CVE-2018-13802A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged user account accessEPSS 3.6%CVE-2020-3227CRITICALCisco IOx for IOS XE Software Privilege Escalation VulnerabilityEPSS 3.4%CVE-2017-3819A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 EPSS 3.3%