Fallos del tipo CWE-290

515 resultados

Autenticação inadequada sujeita a falsificação de identidade

Ocorre quando o mecanismo de autenticação é implementado de forma fraca ou incompleta, permitindo que um atacante se faça passar por outro usuário ou sistema sem precisar das credenciais legítimas. O risco é grave: qualquer um pode ganhar acesso não autorizado simplesmente contornando ou falsificando a identidade.

Ejemplo

Um app que autentica usuários apenas verificando um header HTTP customizado (tipo 'X-User-ID: 123') sem validação criptográfica real. Um atacante muda esse header para 'X-User-ID: admin' e consegue acesso à conta administrativa. Ou um serviço que aceita requisições apenas porque vêm de um IP específico, sem verificar certificados ou assinaturas.

Cómo mitigar

Use protocolos de autenticação estabelecidos (OAuth 2.0, JWT com assinatura, SAML) em vez de inventar o seu. Sempre valide credenciais no servidor com mecanismos criptográficos (hash, assinatura digital, certificados). Nunca confie em headers HTTP, IPs ou tokens não assinados como prova única de identidade.

CVE-2025-69258CRITICALA LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL EPSS 3.5%CVE-2023-24892HIGHMicrosoft Edge (Chromium-based) Webview2 Spoofing VulnerabilityEPSS 3.5%CVE-2018-15715Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vEPSS 3.5%CVE-2025-59501MEDIUMMicrosoft Configuration Manager Spoofing VulnerabilityEPSS 3.0%CVE-2025-1104MEDIUMD-Link DHP-W310AV authentication spoofingEPSS 2.9%CVE-2021-31209MEDIUMMicrosoft Exchange Server Spoofing VulnerabilityEPSS 2.6%CVE-2017-14003An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and pEPSS 2.6%CVE-2024-23832CRITICALMastodon Remote user impersonation and takeoverEPSS 2.5%CVE-2022-34716MEDIUM.NET Spoofing VulnerabilityEPSS 2.3%CVE-2022-26910MEDIUMSkype for Business and Lync Spoofing VulnerabilityEPSS 2.3%CVE-2020-26276CRITICALSAML authentication vulnerability in FleetEPSS 2.2%CVE-2019-18259In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.EPSS 2.1%CVE-2022-29165CRITICALArgo CD will blindly trust JWT claims if anonymous access is enabledEPSS 2.0%CVE-2024-6678CRITICALAuthentication Bypass by Spoofing in GitLabEPSS 2.0%CVE-2020-17516Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryEPSS 1.9%CVE-2021-31172HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.8%CVE-2021-43310CRITICALA vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent wereEPSS 1.8%CVE-2021-21310MEDIUMToken verification bug in next-authEPSS 1.7%CVE-2023-33140MEDIUMMicrosoft OneNote Spoofing VulnerabilityEPSS 1.6%CVE-2021-28478HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.6%