目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-1390 类漏洞列表 78

CWE-1390 类弱点 78 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-1390 属于弱认证漏洞,指产品使用的认证机制无法充分验证用户身份的真实性。攻击者通常利用此缺陷,以较低成本或更快速度绕过身份验证,从而非法获取系统访问权限。开发者应避免使用默认凭证、简单密码或易被破解的算法,转而实施多因素认证、强密码策略及定期密钥轮换,确保身份验证过程具备足够的抗攻击能力。

MITRE CWE 官方描述
CWE:CWE-1390 Weak Authentication(弱认证) 英文:The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct. 译文:该产品使用一种认证机制来限制对特定用户或身份的访问,但该机制未能充分证明所声称的身份是正确的。 Attackers may be able to bypass weak authentication faster and/or with less effort than expected. 译文:攻击者可能能够比预期更快地和/或更轻松地绕过弱认证。
常见影响 (1)
Integrity, Confidentiality, Availability, Access Control Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands
This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
代码示例 (1)
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-77483 SQL Server 权限提升漏洞 — Microsoft SQL Server 2017 (CU 31) 8.8 High 2026-09-08
CVE-2026-73025 Windows iSCSI 安全特性绕过漏洞 — Windows 10 Version 1607 9.8 Critical 2026-09-08
CVE-2026-80219 hawtio-operator OAuth客户端令牌窃取漏洞 — Red Hat build of Apache Camel - HawtIO 4 8.7 High 2026-09-08
CVE-2026-73819 Ebyte NA111-M 授权问题漏洞 — Ebyte NA111-M Firmware 9.8 Critical 2026-08-31
CVE-2026-65098 NVIDIA NemoClaw 授权问题漏洞 — NemoClaw 8.1 High 2026-08-25
CVE-2026-68067 Quanovate Mira Firmware 授权问题漏洞 — Mira Firmware 9.8 Critical 2026-08-11
CVE-2026-59135 Microsoft Windows Search Component 授权问题漏洞 — Windows 10 Version 1607 5.5 Medium 2026-08-11
CVE-2026-59554 WordPress Ziina 授权问题漏洞 — Ziina 7.5 High 2026-07-23
CVE-2026-55040 Microsoft Office Sharepoint Server 授权问题漏洞 — Microsoft SharePoint Enterprise Server 2016 9.1 Critical 2026-07-14
CVE-2026-10714 Rockwell Automation FactoryTalk® Services Platform 授权问题漏洞 — FactoryTalk® Services Platform - - 2026-07-14
CVE-2026-57352 VillaTheme ALD 授权问题漏洞 — ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce 4.8 Medium 2026-07-02
CVE-2026-0274 Palo Alto Networks Cortex XSIAM CommvaultSecurityIQ Marketplace和Palo Alto Networks Cortex XSOAR CommvaultSecurityIQ Marketplace 安全漏洞 — Cortex XSIAM CommvaultSecurityIQ Marketplace - - 2026-06-10
CVE-2026-44237 FreePBX 安全漏洞 — security-reporting - - 2026-05-29
CVE-2026-49323 Indian Motorcycle Scout Bobber + Tech 安全漏洞 — Scout Bobber + Tech 4.3 Medium 2026-05-29
CVE-2026-49322 Indian Motorcycle Scout Bobber + Tech 安全漏洞 — Scout Bobber + Tech 4.3 Medium 2026-05-29
CVE-2026-40417 Microsoft Dynamics 365 安全漏洞 — Microsoft Dynamics 365 Business Central 2024 Release Wave 2 7.8 High 2026-05-12
CVE-2026-0204 SonicWALL SonicOS 访问控制错误漏洞 — SonicOS 9.1AI Critical AI 2026-04-29
CVE-2026-6886 BorG SPM 安全漏洞 — Borg SPM 2007 9.8 Critical 2026-04-23
CVE-2026-4924 Devolutions Server 安全漏洞 — Server 8.8AI High AI 2026-04-01
CVE-2026-4828 Devolutions Server 安全漏洞 — Server 8.1AI High AI 2026-04-01
CVE-2026-32497 WordPress plugin User Verification 安全漏洞 — User Verification 5.3 Medium 2026-03-25
CVE-2025-62844 QNAP Systems QHora 安全漏洞 — QuRouter 5.5 - 2026-03-20
CVE-2026-28710 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect 17 9.1 - 2026-03-05
CVE-2025-15595 Inno Setup 安全漏洞 — Inno Setup 7.8AI High AI 2026-03-03
CVE-2026-1693 PcVue 安全漏洞 — PcVue 9.1AI Critical AI 2026-02-26
CVE-2025-30412 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect 16 9.1AI Critical AI 2026-02-20
CVE-2025-30411 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect 16 9.1AI Critical AI 2026-02-20
CVE-2025-57713 QNAP Systems File Station 5 安全漏洞 — File Station 5 7.5AI High AI 2026-02-11
CVE-2025-40554 SolarWinds Web Help Desk 安全漏洞 — Web Help Desk 9.8 Critical 2026-01-28
CVE-2025-40552 SolarWinds Web Help Desk 安全漏洞 — Web Help Desk 9.8 Critical 2026-01-28

CWE-1390 是常见的弱点类别,本平台收录该类弱点关联的 78 条 CVE 漏洞。