VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 100 of 253
  • CVE-2024-56335HigDec 20, 2024
    risk 0.49cvss 7.6epss 0.00

    vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a user account in the server. 2.…

  • CVE-2024-6248HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not required to exploit this…

  • CVE-2024-11494HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.01

    **UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could allow an unauthenticated attacker to read some device information via a crafted HTTP HEAD method.

  • CVE-2024-46943HigSep 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.

  • CVE-2024-45113HigSep 13, 2024
    risk 0.49cvss 7.5epss 0.01

    ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access and affect the integrity of the application. Exploitation…

  • CVE-2024-7401HigAug 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll…

  • CVE-2024-36132HigAug 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

  • CVE-2024-37368HigJun 14, 2024
    risk 0.49cvss 7.5epss 0.01

    A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this…

  • CVE-2024-37367HigJun 14, 2024
    risk 0.49cvss 7.5epss 0.01

    A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper…

  • CVE-2023-46630HigJun 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Admin and Site Enhancements (ASE): from n/a through 5.7.1.

  • CVE-2024-4024HigApr 25, 2024
    risk 0.49cvss 7.3epss 0.15

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials…

  • CVE-2023-52540HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-25652HigMar 14, 2024
    risk 0.49cvss 7.6epss 0.01

    In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by…

  • CVE-2024-21427HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Kerberos Security Feature Bypass Vulnerability

  • CVE-2023-46717HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts.

  • CVE-2023-48703HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.01

    RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` command line tool is called internally to verify the signature of SAML assertions. When `xmlsec1` is used…

  • CVE-2022-41738HigFeb 17, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.

  • CVE-2023-50275HigJan 23, 2024
    risk 0.49cvss 7.5epss 0.01

    HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

  • CVE-2023-52111HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2024-21632HigJan 2, 2024
    risk 0.49cvss 8.6epss 0.01

    omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth…