VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 110 of 241
  • CVE-2024-45750HigSep 25, 2024
    risk 0.47cvss 7.3epss 0.01

    An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and…

  • CVE-2024-7346HigSep 3, 2024
    risk 0.47cvss 7.2epss 0.00

    Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection.  This has been corrected so that default certificates are no longer capable of overriding host name…

  • CVE-2022-4002HigJul 31, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

  • CVE-2022-4001HigJul 31, 2024
    risk 0.47cvss 7.3epss 0.00

    An authentication bypass vulnerability could allow an attacker to access API functions without authentication.

  • CVE-2024-37408HigJun 8, 2024
    risk 0.47cvss 7.3epss 0.00

    fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to…

  • CVE-2024-29757HigApr 5, 2024
    risk 0.47cvss 7.3epss 0.00

    there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-23813HigFeb 13, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potentially execute code.

  • CVE-2023-29975HigNov 9, 2023
    risk 0.47cvss 7.2epss 0.02

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

  • CVE-2023-36815HigJul 3, 2023
    risk 0.47cvss 7.3epss 0.01

    Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the…

  • CVE-2023-35154HigJun 23, 2023
    risk 0.47cvss 7.2epss 0.00

    Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allowing them access to the application as a…

  • CVE-2023-1477HigApr 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.

  • CVE-2023-27091HigApr 4, 2023
    risk 0.47cvss 7.2epss 0.01

    An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).

  • CVE-2022-37931HigNov 22, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.

  • CVE-2022-3674HigOct 26, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The identifier…

  • CVE-2022-35203HigAug 23, 2022
    risk 0.47cvss 7.2epss 0.01

    An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.

  • CVE-2022-2664HigAug 5, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It…

  • CVE-2017-20133HigJul 16, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.

  • CVE-2022-30755HigJul 12, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.

  • CVE-2022-30229HigJun 14, 2022
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case…

  • CVE-2021-30028HigMay 20, 2022
    risk 0.47cvss 7.2epss 0.01

    SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.