VYPR

CWE-1270

Generation of Incorrect Security Tokens

BaseIncomplete

Description

The product implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens generated in the system are incorrect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-121 · CAPEC-633 · CAPEC-681

CVEs mapped to this weakness (10)

  • CVE-2023-2882CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

  • CVE-2022-31122CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain details of SAML IdP metadata, and configures their own SAML on the same backend, the attacker can delete…

  • CVE-2023-32188CriOct 16, 2024
    risk 0.54cvss epss 0.00

    A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

  • CVE-2026-54593HigJul 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's…

  • CVE-2025-59698MedDec 2, 2025
    risk 0.44cvss 6.8epss 0.00

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate attacker to gain access to the EOL legacy bootloader.

  • CVE-2023-22644MedSep 20, 2023
    risk 0.36cvss 5.5epss 0.00

    A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

  • CVE-2023-30524MedApr 12, 2023
    risk 0.28cvss 4.3epss 0.00

    Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2026-15831MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization…

  • CVE-2026-49499HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2014-2237Apr 1, 2014
    risk 0.00cvss epss 0.01

    The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the…