VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 103 of 253
  • CVE-2022-25027HigJan 12, 2023
    risk 0.49cvss 7.5epss 0.01

    The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

  • CVE-2022-47976HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.

  • CVE-2022-46170HigDec 22, 2022
    risk 0.49cvss 8.6epss 0.01

    CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one…

  • CVE-2021-35252HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

  • CVE-2022-25685HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-40242HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    MegaRAC Default Credentials Vulnerability

  • CVE-2022-20918HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS)…

  • CVE-2022-25667HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking

  • CVE-2022-36370HigNov 11, 2022
    risk 0.49cvss 7.5epss 0.00

    Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-38744HigOct 27, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages…

  • CVE-2022-23769HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution.

  • CVE-2022-39254HigSep 29, 2022
    risk 0.49cvss 8.6epss 0.01

    matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without…

  • CVE-2022-39252HigSep 29, 2022
    risk 0.49cvss 8.6epss 0.01

    matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives…

  • CVE-2022-39250HigSep 29, 2022
    risk 0.49cvss 8.6epss 0.01

    Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user…

  • CVE-2022-39251HigSep 28, 2022
    risk 0.49cvss 8.6epss 0.01

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield.…

  • CVE-2022-39248HigSep 28, 2022
    risk 0.49cvss 8.6epss 0.01

    matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a…

  • CVE-2022-22523HigSep 28, 2022
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.

  • CVE-2022-3119HigSep 26, 2022
    risk 0.49cvss 7.5epss 0.00

    The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated…

  • CVE-2022-39801HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to…

  • CVE-2022-35198HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.