VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 100 of 241
  • CVE-2019-20618HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated unpinning of an app. The Samsung ID is SVE-2018-13765 (March 2019).

  • CVE-2019-20565HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configuration without authentication. The Samsung ID is SVE-2018-13300 (September 2019).

  • CVE-2020-10669HigMar 19, 2020
    risk 0.49cvss 7.5epss 0.04

    The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is…

  • CVE-2020-6988HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.04

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the…

  • CVE-2018-15819HigMar 2, 2020
    risk 0.49cvss 7.5epss 0.02

    EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.

  • CVE-2013-6360HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.01

    TRENDnet TS-S402 has a backdoor to enable TELNET.

  • CVE-2016-2032HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672

  • CVE-2012-3824HigJan 10, 2020
    risk 0.49cvss 7.5epss 0.02

    In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

  • CVE-2019-20360HigJan 8, 2020
    risk 0.49cvss 7.5epss 0.02

    A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta…

  • CVE-2018-19834HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.01

    The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

  • CVE-2018-19833HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.01

    The owned function of a smart contract implementation for DDQ, an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

  • CVE-2018-19832HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.01

    The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

  • CVE-2018-19831HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.01

    The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

  • CVE-2019-18320HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could be able to upload arbitrary files without authentication. Please note that an attacker needs to have…

  • CVE-2019-18319HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-18318HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server can cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-18317HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-16201HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.05

    WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.

  • CVE-2014-2904HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.01

    wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

  • CVE-2019-18661HigNov 2, 2019
    risk 0.49cvss 7.5epss 0.02

    Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, the attacker can view all of the web pages of the administration console.