VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 105 of 253
  • CVE-2022-25508HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.

  • CVE-2022-23317HigFeb 15, 2022
    risk 0.49cvss 7.5epss 0.01

    CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.

  • CVE-2021-45347HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.

  • CVE-2022-23320HigFeb 7, 2022
    risk 0.49cvss 7.5epss 0.02

    XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.

  • CVE-2021-40851HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.

  • CVE-2021-39064HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.

  • CVE-2021-21955HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.

  • CVE-2021-20145HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make…

  • CVE-2021-37054HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-41311HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/…

  • CVE-2021-43175HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOautodial validate the username and password…

  • CVE-2021-37100HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.

  • CVE-2021-37043HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious application processes occupy system resources.

  • CVE-2021-43203HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.

  • CVE-2021-41312HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the…

  • CVE-2021-22473HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-37624HigOct 25, 2021
    risk 0.49cvss 7.5epss 0.04

    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam…

  • CVE-2021-30312HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30302HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2021-37414HigSep 10, 2021
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.