VYPR

CWE-1390

Weak Authentication

ClassIncomplete

Description

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Hierarchy (View 1000)

CVEs mapped to this weakness (89)

page 4 of 5
  • CVE-2025-47995MedJul 18, 2025
    risk 0.42cvss 6.5epss 0.01

    Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-32885MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom message (into existing v1 networks) with any GID and Callsign via a software defined radio. This can be exploited if the device is being used in…

  • CVE-2025-26635MedApr 8, 2025
    risk 0.42cvss 6.5epss 0.01

    Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.

  • CVE-2025-21552MedJan 21, 2025
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2024-47127MedSep 26, 2024
    risk 0.42cvss 6.5epss 0.00

    In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted…

  • CVE-2024-41722MedSep 26, 2024
    risk 0.42cvss 6.5epss 0.00

    In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an …

  • CVE-2024-6580MedJul 8, 2024
    risk 0.42cvss 6.5epss 0.00

    The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without…

  • CVE-2023-4094MedSep 19, 2023
    risk 0.42cvss 6.5epss 0.00

    ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the…

  • CVE-2023-24890MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

  • CVE-2024-45551MedApr 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.

  • CVE-2026-59135MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

  • CVE-2025-62844MedMar 20, 2026
    risk 0.36cvss 5.5epss 0.00

    A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later

  • CVE-2026-32497MedMar 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45.

  • CVE-2025-47479MedJul 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This issue affects WP Compress: from n/a through <= 6.30.30.

  • CVE-2023-41862MedDec 13, 2024
    risk 0.34cvss 5.3epss 0.01

    Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0.

  • CVE-2022-45860MedMay 3, 2023
    risk 0.34cvss 5.3epss 0.00

    A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying…

  • CVE-2024-32119MedJun 10, 2025
    risk 0.31cvss 4.8epss 0.00

    An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted…

  • CVE-2025-0605MedMay 22, 2025
    risk 0.30cvss 4.6epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.

  • CVE-2026-49323MedMay 29, 2026
    risk 0.28cvss 4.3epss 0.00

    Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM…

  • CVE-2026-49322MedMay 29, 2026
    risk 0.28cvss 4.3epss 0.00

    Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN…