CWE-287 · 4 533 записей
Некорректная аутентификация
Почему это происходит?
Аутентификация добавляется к каждому маршруту по отдельности, а не обеспечивается централизованно. Если маршрут, добавленный позже, обходит общий промежуточный обработчик, проверка сессии для него не выполняется вовсе.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
app.use("/admin", requireSession, adminRouter);
// Добавленный позже маршрут обходит обработчикapp.post("/admin-api/config", updateConfig);Исправленный код
const admin = express.Router();admin.use(requireSession, requireRole("admin"));
admin.post("/config", updateConfig);app.use("/admin", admin);Как предотвратить
- 01Обеспечивайте аутентификацию на уровне маршрутизатора, в едином промежуточном обработчике.
- 02Запрещайте по умолчанию: открытые эндпоинты перечисляйте в списке разрешённых.
- 03В тестах вызывайте каждый административный маршрут без сессии и проверяйте, что он возвращает 401.
CVE этого класса
4 538 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2024-7593Готовый эксплойт | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated aivanti · virtual traffic manager · CWE-287 | Критическая9,8 | KEV | 100,0 % | 13 авг. 2024 г. |
99Срочно | CVE-2023-35078Готовый эксплойт | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appliivanti · endpoint manager mobile · CWE-287 | Критическая9,8 | KEV | 100,0 % | 25 июл. 2023 г. |
99Срочно | CVE-2023-35082Готовый эксплойт | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resouivanti · endpoint manager mobile · CWE-287 | Критическая9,8 | KEV | 100,0 % | 15 авг. 2023 г. |
99Срочно | CVE-2017-7921Готовый эксплойт | An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I hikvision · ds-2cd2032-i firmware · CWE-287 | Критическая9,8 | KEV | 100,0 % | 5 мая 2017 г. |
99Срочно | CVE-2021-33044Готовый эксплойт | The identity authentication bypass vulnerability found in some Dahua products during the login process.dahuasecurity · ipc-hum7xxx firmware · CWE-287 | Критическая9,8 | KEV | 100,0 % | 15 сент. 2021 г. |
99Срочно | CVE-2022-40684Готовый эксплойт | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.fortinet · fortiproxy · CWE-287 | Критическая9,8 | KEV | 100,0 % | 18 окт. 2022 г. |
99Срочно | CVE-2025-61882Готовый эксплойт | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).oracle · concurrent processing · CWE-287 | Критическая9,8 | KEV | 99,7 % | 5 окт. 2025 г. |
99Срочно | CVE-2021-33045Готовый эксплойт | The identity authentication bypass vulnerability found in some Dahua products during the login process.dahuasecurity · ipc-hum7xxx firmware · CWE-287 | Критическая9,8 | KEV | 99,6 % | 15 сент. 2021 г. |
99Срочно | CVE-2021-32030Готовый эксплойт | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authenticatioasus · lyra mini firmware · CWE-287 | Критическая9,8 | KEV | 99,4 % | 6 мая 2021 г. |
98Срочно | CVE-2024-53704Готовый эксплойт | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.sonicwall · sonicos · CWE-287 | Критическая9,8 | KEV | 95,1 % | 9 янв. 2025 г. |
97Срочно | CVE-2013-0625Готовый эксплойт | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeadobe · coldfusion · CWE-287 | Критическая9,8 | KEV | 93,8 % | 8 янв. 2013 г. |
97Срочно | CVE-2018-10561Готовый эксплойт | An issue was discovered on Dasan GPON home routers.dasannetworks · gpon router firmware · CWE-287 | Критическая9,8 | KEV | 92,9 % | 3 мая 2018 г. |
97Срочно | CVE-2026-20182Готовый эксплойт | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerabilitycisco · catalyst sd-wan manager · CWE-287 | Критическая10,0 | KEV | 91,5 % | 14 мая 2026 г. |
97Срочно | CVE-2026-20127Готовый эксплойт | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerabilitycisco · catalyst sd-wan manager · CWE-287 | Критическая10,0 | KEV | 88,5 % | 25 февр. 2026 г. |
95Срочно | CVE-2020-0688Готовый эксплойт | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, akmicrosoft · exchange server · CWE-287 | Высокая8,8 | KEV | 100,0 % | 11 февр. 2020 г. |
94Срочно | CVE-2015-1187Готовый эксплойт | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ctrendnet · tew-731br firmware · CWE-287 | Критическая9,8 | KEV | 82,9 % | 21 сент. 2017 г. |
93Срочно | CVE-2021-32648Готовый эксплойт | Account Takeover in Octobercmsoctobercms · october · CWE-287 | Критическая9,1 | KEV | 90,4 % | 26 авг. 2021 г. |
92Срочно | CVE-2023-46805Готовый эксплойт | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to accivanti · connect secure · CWE-287 | Высокая8,2 | KEV | 100,0 % | 12 янв. 2024 г. |
90Срочно | CVE-2026-16232Готовый эксплойт | Authentication Bypass in the SmartConsole Login Process Using an Application Tokencheckpoint · multi-domain security management · CWE-287 | Критическая9,3 | KEV | 78,0 % | 22 июл. 2026 г. |
90Срочно | CVE-2020-4427Готовый эксплойт | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configibm · data risk manager · CWE-287 | Критическая9,8 | KEV | 70,0 % | 7 мая 2020 г. |
89Срочно | CVE-2021-39226Готовый эксплойт | Snapshot authentication bypass in grafanagrafana · grafana · CWE-287 | Высокая7,3 | KEV | 99,9 % | 5 окт. 2021 г. |
89Срочно | CVE-2023-28461Готовый эксплойт | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution.arraynetworks · arrayos ag · CWE-287 | Критическая9,8 | KEV | 68,1 % | 15 мар. 2023 г. |
87Срочно | CVE-2015-7755Готовый эксплойт | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 beforejuniper · screenos · CWE-287 | Критическая9,8 | KEV | 61,1 % | 19 дек. 2015 г. |
86Срочно | CVE-2025-49706Готовый эксплойт | Microsoft SharePoint Server Spoofing Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-287 | Средняя6,5 | KEV | 99,1 % | 8 июл. 2025 г. |
86Срочно | CVE-2019-19006Готовый эксплойт | Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.sangoma · freepbx · CWE-287 | Критическая9,8 | KEV | 55,9 % | 21 нояб. 2019 г. |
- CVE-2024-759399Срочно
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · virtual traffic manager13 авг. 2024 г.
- CVE-2023-3507899Срочно
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager mobile25 июл. 2023 г.
- CVE-2023-3508299Срочно
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager mobile15 авг. 2023 г.
- CVE-2017-792199Срочно
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %hikvision · ds-2cd2032-i firmware5 мая 2017 г.
- CVE-2021-3304499Срочно
The identity authentication bypass vulnerability found in some Dahua products during the login process.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dahuasecurity · ipc-hum7xxx firmware15 сент. 2021 г.
- CVE-2022-4068499Срочно
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortinet · fortiproxy18 окт. 2022 г.
- CVE-2025-6188299Срочно
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · concurrent processing5 окт. 2025 г.
- CVE-2021-3304599Срочно
The identity authentication bypass vulnerability found in some Dahua products during the login process.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dahuasecurity · ipc-hum7xxx firmware15 сент. 2021 г.
- CVE-2021-3203099Срочно
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authenticatio
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %asus · lyra mini firmware6 мая 2021 г.
- CVE-2024-5370498Срочно
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %sonicwall · sonicos9 янв. 2025 г.
- CVE-2013-062597Срочно
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · coldfusion8 янв. 2013 г.
- CVE-2018-1056197Срочно
An issue was discovered on Dasan GPON home routers.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %dasannetworks · gpon router firmware3 мая 2018 г.
- CVE-2026-2018297Срочно
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 92 %cisco · catalyst sd-wan manager14 мая 2026 г.
- CVE-2026-2012797Срочно
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 88 %cisco · catalyst sd-wan manager25 февр. 2026 г.
- CVE-2020-068895Срочно
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, ak
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %microsoft · exchange server11 февр. 2020 г.
- CVE-2015-118794Срочно
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.c
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %trendnet · tew-731br firmware21 сент. 2017 г.
- CVE-2021-3264893Срочно
Account Takeover in Octobercms
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 90 %octobercms · october26 авг. 2021 г.
- CVE-2023-4680592Срочно
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to acc
ВысокаяCVSS 8,2KEVГотовый эксплойтEPSS 100 %ivanti · connect secure12 янв. 2024 г.
- CVE-2026-1623290Срочно
Authentication Bypass in the SmartConsole Login Process Using an Application Token
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 78 %checkpoint · multi-domain security management22 июл. 2026 г.
- CVE-2020-442790Срочно
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when config
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 70 %ibm · data risk manager7 мая 2020 г.
- CVE-2021-3922689Срочно
Snapshot authentication bypass in grafana
ВысокаяCVSS 7,3KEVГотовый эксплойтEPSS 100 %grafana · grafana5 окт. 2021 г.
- CVE-2023-2846189Срочно
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 68 %arraynetworks · arrayos ag15 мар. 2023 г.
- CVE-2015-775587Срочно
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 61 %juniper · screenos19 дек. 2015 г.
- CVE-2025-4970686Срочно
Microsoft SharePoint Server Spoofing Vulnerability
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 99 %microsoft · sharepoint enterprise server8 июл. 2025 г.
- CVE-2019-1900686Срочно
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 56 %sangoma · freepbx21 нояб. 2019 г.