VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 101 of 253
  • CVE-2023-6847HigDec 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafted API request. To exploit this vulnerability, an attacker would need network access to the Enterprise Server appliance configured…

  • CVE-2023-51442HigDec 21, 2023
    risk 0.49cvss 8.6epss 0.01

    Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endpoint, allowing for authentication bypass. This exploit enables unauthorized access to any known account by utilizing a JSON Web…

  • CVE-2023-45801HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.

  • CVE-2023-36004HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability

  • CVE-2023-5808HigDec 5, 2023
    risk 0.49cvss 7.6epss 0.01

    SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that…

  • CVE-2023-35137HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain system information by sending a crafted URL to a vulnerable…

  • CVE-2023-39345HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in…

  • CVE-2023-5627HigNov 1, 2023
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web…

  • CVE-2023-44397HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.01

    CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this…

  • CVE-2023-27377HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.

  • CVE-2023-44096HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-0813HigSep 15, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows…

  • CVE-2022-47848HigSep 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml page of the UPnP service.

  • CVE-2023-39981HigSep 2, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker.

  • CVE-2023-25913HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.

  • CVE-2023-39415HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel…

  • CVE-2023-3263HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid…

  • CVE-2023-39380HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

  • CVE-2023-33363HigAug 3, 2023
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers.

  • CVE-2023-2626HigJul 25, 2023
    risk 0.49cvss 7.5epss 0.00

    There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks,…