CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,056)
page 102 of 253| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2959 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2023 | Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2. | ||
| CVE-2023-3127 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2023 | An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights. | ||
| CVE-2023-35940 | Hig | 0.49 | 7.5 | 0.01 | Jul 5, 2023 | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue. | ||
| CVE-2022-48496 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2023 | Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized. | ||
| CVE-2022-48494 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2023 | Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized. | ||
| CVE-2023-30223 | Hig | 0.49 | 7.5 | 0.01 | Jun 16, 2023 | A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions. | ||
| CVE-2022-40536 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2023-30063 | Hig | 0.49 | 7.5 | 0.01 | May 1, 2023 | D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass. | ||
| CVE-2023-30061 | Hig | 0.49 | 7.5 | 0.01 | May 1, 2023 | D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi. | ||
| CVE-2022-45456 | Hig | 0.49 | 7.5 | 0.00 | Apr 26, 2023 | Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161. | ||
| CVE-2023-21027 | Hig | 0.49 | 7.5 | 0.00 | Mar 24, 2023 | In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-25264 | Hig | 0.49 | 7.5 | 0.01 | Feb 28, 2023 | An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments. | ||
| CVE-2022-47508 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2023 | Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos. | ||
| CVE-2022-48294 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2020-20402 | Hig | 0.49 | 7.5 | 0.01 | Jan 31, 2023 | Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation. | ||
| CVE-2022-4441 | Hig | 0.49 | 7.6 | 0.01 | Jan 31, 2023 | Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 04.9.1. | ||
| CVE-2023-24830 | Hig | 0.49 | 7.5 | 0.01 | Jan 30, 2023 | Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3. | ||
| CVE-2021-43444 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key. | ||
| CVE-2023-21841 | Hig | 0.49 | 7.5 | 0.01 | Jan 18, 2023 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP… |
- risk 0.49cvss 7.5epss 0.01
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
- risk 0.49cvss 7.5epss 0.01
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
- risk 0.49cvss 7.5epss 0.01
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
- risk 0.49cvss 7.5epss 0.00
Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161.
- risk 0.49cvss 7.5epss 0.00
In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.
- risk 0.49cvss 7.5epss 0.01
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.
- risk 0.49cvss 7.5epss 0.00
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.
- risk 0.49cvss 7.6epss 0.01
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 04.9.1.
- risk 0.49cvss 7.5epss 0.01
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.
- risk 0.49cvss 7.5epss 0.01
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP…