VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 107 of 253
  • CVE-2021-22496HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.

  • CVE-2020-23355HigJan 27, 2021
    risk 0.49cvss 7.5epss 0.01

    ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234…

  • CVE-2020-28874HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.02

    reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

  • CVE-2020-24641HigJan 15, 2021
    risk 0.49cvss 7.5epss 0.01

    In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately…

  • CVE-2020-5686HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.01

    Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific…

  • CVE-2020-36176HigJan 6, 2021
    risk 0.49cvss 7.5epss 0.01

    The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

  • CVE-2020-27254HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to…

  • CVE-2020-27199HigDec 17, 2020
    risk 0.49cvss 7.5epss 0.03

    The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token…

  • CVE-2020-0460HigDec 14, 2020
    risk 0.49cvss 7.5epss 0.01

    In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-27408HigDec 4, 2020
    risk 0.49cvss 7.5epss 0.02

    OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.

  • CVE-2020-8272HigNov 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

  • CVE-2020-25165HigNov 13, 2020
    risk 0.49cvss 7.5epss 0.02

    BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a network session authentication vulnerability within the authentication process between specified versions of the BD…

  • CVE-2020-15949HigNov 5, 2020
    risk 0.49cvss 7.5epss 0.01

    Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.

  • CVE-2020-27178HigOct 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.

  • CVE-2020-10816HigOct 8, 2020
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.

  • CVE-2020-26511HigOct 2, 2020
    risk 0.49cvss 7.5epss 0.02

    The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.

  • CVE-2018-11765HigSep 30, 2020
    risk 0.49cvss 7.5epss 0.05

    In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

  • CVE-2020-8253HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.02

    Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.

  • CVE-2020-3411HigAug 17, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker could exploit this…

  • CVE-2020-13290HigAug 12, 2020
    risk 0.49cvss 7.5epss 0.01

    In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page