VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 109 of 253
  • CVE-2018-19834HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.01

    The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

  • CVE-2018-19833HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.01

    The owned function of a smart contract implementation for DDQ, an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

  • CVE-2018-19832HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.01

    The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

  • CVE-2018-19831HigDec 31, 2019
    risk 0.49cvss 7.5epss 0.01

    The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

  • CVE-2019-18320HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could be able to upload arbitrary files without authentication. Please note that an attacker needs to have…

  • CVE-2019-18319HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-18318HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server can cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-18317HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is…

  • CVE-2019-16201HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.05

    WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.

  • CVE-2014-2904HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.01

    wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

  • CVE-2019-18661HigNov 2, 2019
    risk 0.49cvss 7.5epss 0.02

    Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, the attacker can view all of the web pages of the administration console.

  • CVE-2019-16929HigOct 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.

  • CVE-2019-12664HigSep 25, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to successful PPP…

  • CVE-2019-16250HigSep 11, 2019
    risk 0.49cvss 7.5epss 0.01

    includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.

  • CVE-2019-15046HigAug 14, 2019
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.

  • CVE-2016-10833HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).

  • CVE-2017-8405HigJul 2, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered on D-Link DCS-1130 and DCS-1100 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary loads at address 0x00012CF4 a flag called "Authenticate" that indicates whether a…

  • CVE-2019-7579HigJun 17, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.187766/dynamic/js/setup.js.localized file on the router's webserver, allowing for an attacker to identify possible passwords that…

  • CVE-2018-7340HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.01

    Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially…

  • CVE-2019-9496HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.05

    An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd…