Falhas do tipo CWE-1390

86 resultados

Autenticação fraca

Fraqueza em que o mecanismo de autenticação não valida suficientemente a identidade do usuário, aceitando credenciais insuficientes, previsíveis ou sem proteção adequada. Um atacante consegue contornar a autenticação com pouco esforço, obtendo acesso não autorizado ao sistema.

Exemplo

Um app que permite login apenas com username (sem senha), ou um serviço que usa tokens de autenticação hardcoded que nunca expiram, ou ainda uma API que valida acesso só verificando se um campo numérico simples está presente na requisição.

Como mitigar

Implemente autenticação multifatorial, use hashing forte para senhas (bcrypt, Argon2), enforce expiração de tokens, valide credenciais contra armazenamento seguro sem padrões previsíveis, e aplique rate limiting em tentativas de login. Considere OAuth 2.0 ou SAML para delegação segura.

CVE-2025-23058HIGHAuthenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.7%CVE-2025-30411CRITICALSensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (LiEPSS 0.7%CVE-2025-12870CRITICALaEnrich|eHRD - Authentication AbuseEPSS 0.6%CVE-2025-47995MEDIUMAzure Machine Learning Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-30412CRITICALSensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (LiEPSS 0.6%CVE-2025-7326HIGHEOL ASP.NET Core Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-12871CRITICALaEnrich|a+HRD - Authentication AbuseEPSS 0.6%CVE-2025-49201HIGHA weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all veEPSS 0.6%CVE-2023-41862MEDIUMWordPress VS Contact Form plugin <= 14.0 - Sum Captcha Bypass vulnerabilityEPSS 0.6%CVE-2023-53894CRITICALphpfm 1.7.9 Authentication Bypass via Type Juggling VulnerabilityEPSS 0.6%CVE-2024-50563MEDIUMA weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud vEPSS 0.6%CVE-2024-36787HIGHAn issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface EPSS 0.6%CVE-2025-1387CRITICALLearning Digital Orca HCM - Improper AuthenticationEPSS 0.6%CVE-2025-39596CRITICALWordPress Quentn WP plugin <= 1.2.8 - Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-13239CRITICALTwo-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2024-003EPSS 0.6%CVE-2025-1727HIGHEnd-of-Train and Head-of-Train Remote Linking Protocol Weak AuthenticationEPSS 0.5%CVE-2025-31676HIGHEmail TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001EPSS 0.5%CVE-2025-57713LOWFile Station 5EPSS 0.5%CVE-2024-29837HIGHPoor session management in Evolution Controller allows administrator functionality for unauthenticated connectionsEPSS 0.5%CVE-2024-45367CRITICALOptigo Networks ONS-S8 Spectra Aggregation Switch Weak AuthenticationEPSS 0.5%