VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 102 of 253
  • CVE-2023-2959HigJul 17, 2023
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.

  • CVE-2023-3127HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

  • CVE-2023-35940HigJul 5, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.

  • CVE-2022-48496HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.

  • CVE-2022-48494HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.

  • CVE-2023-30223HigJun 16, 2023
    risk 0.49cvss 7.5epss 0.01

    A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.

  • CVE-2022-40536HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.

  • CVE-2022-40521HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to improper authorization in Modem

  • CVE-2023-30063HigMay 1, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.

  • CVE-2023-30061HigMay 1, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.

  • CVE-2022-45456HigApr 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161.

  • CVE-2023-21027HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-25264HigFeb 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.

  • CVE-2022-47508HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.

  • CVE-2022-48294HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2020-20402HigJan 31, 2023
    risk 0.49cvss 7.5epss 0.01

    Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.

  • CVE-2022-4441HigJan 31, 2023
    risk 0.49cvss 7.6epss 0.01

    Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 04.9.1.

  • CVE-2023-24830HigJan 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.

  • CVE-2021-43444HigJan 23, 2023
    risk 0.49cvss 7.5epss 0.01

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.

  • CVE-2023-21841HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP…