CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,804)
page 110 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45750 | Hig | 0.47 | 7.3 | 0.01 | Sep 25, 2024 | An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and… | ||
| CVE-2024-7346 | Hig | 0.47 | 7.2 | 0.00 | Sep 3, 2024 | Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. This has been corrected so that default certificates are no longer capable of overriding host name… | ||
| CVE-2022-4002 | Hig | 0.47 | 7.2 | 0.01 | Jul 31, 2024 | A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request. | ||
| CVE-2022-4001 | Hig | 0.47 | 7.3 | 0.00 | Jul 31, 2024 | An authentication bypass vulnerability could allow an attacker to access API functions without authentication. | ||
| CVE-2024-37408 | Hig | 0.47 | 7.3 | 0.00 | Jun 8, 2024 | fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to… | ||
| CVE-2024-29757 | Hig | 0.47 | 7.3 | 0.00 | Apr 5, 2024 | there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-23813 | Hig | 0.47 | 7.3 | 0.01 | Feb 13, 2024 | A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potentially execute code. | ||
| CVE-2023-29975 | Hig | 0.47 | 7.2 | 0.02 | Nov 9, 2023 | An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification. | ||
| CVE-2023-36815 | Hig | 0.47 | 7.3 | 0.01 | Jul 3, 2023 | Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the… | ||
| CVE-2023-35154 | Hig | 0.47 | 7.2 | 0.00 | Jun 23, 2023 | Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allowing them access to the application as a… | ||
| CVE-2023-1477 | Hig | 0.47 | 7.2 | 0.01 | Apr 28, 2023 | Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3. | ||
| CVE-2023-27091 | Hig | 0.47 | 7.2 | 0.01 | Apr 4, 2023 | An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s). | ||
| CVE-2022-37931 | Hig | 0.47 | 7.3 | 0.00 | Nov 22, 2022 | A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details. | ||
| CVE-2022-3674 | Hig | 0.47 | 7.3 | 0.01 | Oct 26, 2022 | A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The identifier… | ||
| CVE-2022-35203 | Hig | 0.47 | 7.2 | 0.01 | Aug 23, 2022 | An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information. | ||
| CVE-2022-2664 | Hig | 0.47 | 7.3 | 0.01 | Aug 5, 2022 | A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It… | ||
| CVE-2017-20133 | Hig | 0.47 | 7.3 | 0.01 | Jul 16, 2022 | A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. | ||
| CVE-2022-30755 | Hig | 0.47 | 7.3 | 0.00 | Jul 12, 2022 | Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent. | ||
| CVE-2022-30229 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case… | ||
| CVE-2021-30028 | Hig | 0.47 | 7.2 | 0.01 | May 20, 2022 | SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely. |
- risk 0.47cvss 7.3epss 0.01
An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and…
- risk 0.47cvss 7.2epss 0.00
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. This has been corrected so that default certificates are no longer capable of overriding host name…
- risk 0.47cvss 7.2epss 0.01
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
- risk 0.47cvss 7.3epss 0.00
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.
- risk 0.47cvss 7.3epss 0.00
fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to…
- risk 0.47cvss 7.3epss 0.00
there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.47cvss 7.3epss 0.01
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potentially execute code.
- risk 0.47cvss 7.2epss 0.02
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
- risk 0.47cvss 7.3epss 0.01
Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the…
- risk 0.47cvss 7.2epss 0.00
Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allowing them access to the application as a…
- risk 0.47cvss 7.2epss 0.01
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.
- risk 0.47cvss 7.2epss 0.01
An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).
- risk 0.47cvss 7.3epss 0.00
A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.
- risk 0.47cvss 7.3epss 0.01
A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The identifier…
- risk 0.47cvss 7.2epss 0.01
An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.
- risk 0.47cvss 7.3epss 0.01
A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It…
- risk 0.47cvss 7.3epss 0.01
A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.
- risk 0.47cvss 7.3epss 0.00
Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.
- risk 0.47cvss 7.2epss 0.01
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case…
- risk 0.47cvss 7.2epss 0.01
SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.