VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 104 of 253
  • CVE-2022-36524HigAug 15, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

  • CVE-2016-0796HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide…

  • CVE-2022-31164HigJul 22, 2022
    risk 0.49cvss 7.5epss 0.01

    Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been patched in version 0.7.51.

  • CVE-2022-34535HigJul 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.

  • CVE-2022-33736HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (All versions < V13.2.20220624). The affected applications do not properly validate login information during authentication. This could lead to denial of service…

  • CVE-2021-41638HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.02

    The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.

  • CVE-2022-1801HigJun 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for…

  • CVE-2022-31083HigJun 17, 2022
    risk 0.49cvss 8.6epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be…

  • CVE-2022-32276HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.04

    Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability

  • CVE-2018-18907HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data Frames to the AP without encryption.

  • CVE-2022-29865HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

  • CVE-2022-30150HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.03

    Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability

  • CVE-2022-21935HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.

  • CVE-2022-30034HigJun 2, 2022
    risk 0.49cvss 8.6epss 0.01

    Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.

  • CVE-2022-26975HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.

  • CVE-2022-29534HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

  • CVE-2021-26627HigApr 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay command and lead to leakage a live image.

  • CVE-2021-46740HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2019-9564HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to…

  • CVE-2021-26620HigMar 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder…