CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,804)
page 114 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34103 | Hig | 0.46 | 8.1 | 0.01 | Jun 13, 2024 | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the… | ||
| CVE-2024-22257 | Hig | 0.46 | 8.2 | 0.01 | Mar 18, 2024 | In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the… | ||
| CVE-2024-21390 | Hig | 0.46 | 7.1 | 0.01 | Mar 12, 2024 | Microsoft Authenticator Elevation of Privilege Vulnerability | ||
| CVE-2022-41737 | Hig | 0.46 | 7.1 | 0.00 | Feb 17, 2024 | IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811. | ||
| CVE-2023-33070 | Hig | 0.46 | 7.1 | 0.00 | Dec 5, 2023 | Transient DOS in Automotive OS due to improper authentication to the secure IO calls. | ||
| CVE-2023-4677 | Hig | 0.46 | 7.0 | 0.00 | Nov 23, 2023 | Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an… | ||
| CVE-2023-39215 | Hig | 0.46 | 7.1 | 0.01 | Sep 12, 2023 | Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2023-21626 | Hig | 0.46 | 7.1 | 0.00 | Aug 8, 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. | ||
| CVE-2023-39349 | Hig | 0.46 | 8.1 | 0.01 | Aug 7, 2023 | Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with… | ||
| CVE-2023-29032 | Hig | 0.46 | 8.1 | 0.01 | May 12, 2023 | An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0 | ||
| CVE-2023-28973 | Hig | 0.46 | 7.1 | 0.00 | Apr 17, 2023 | An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Administrative functions… | ||
| CVE-2021-40342 | Hig | 0.46 | 7.1 | 0.00 | Jan 5, 2023 | In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue… | ||
| CVE-2022-47633 | Hig | 0.46 | 8.1 | 0.01 | Dec 23, 2022 | An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in… | ||
| CVE-2022-46829 | Hig | 0.46 | 7.1 | 0.00 | Dec 8, 2022 | In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented. | ||
| CVE-2022-26870 | Hig | 0.46 | 7.0 | 0.01 | Oct 21, 2022 | Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit. | ||
| CVE-2022-22576 | Hig | 0.46 | 8.1 | 0.02 | May 26, 2022 | An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects… | ||
| CVE-2022-22796 | Hig | 0.46 | 7.0 | 0.01 | May 12, 2022 | Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication. | ||
| CVE-2021-44057 | Hig | 0.46 | 7.1 | 0.01 | May 5, 2022 | An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo… | ||
| CVE-2021-44056 | Hig | 0.46 | 7.1 | 0.01 | May 5, 2022 | An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video… | ||
| CVE-2022-24738 | Hig | 0.46 | 8.1 | 0.01 | Mar 7, 2022 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed funds from user addresses. To do this an attacker must create a new chain which does not enforce signature verification and connects… |
- risk 0.46cvss 8.1epss 0.01
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the…
- risk 0.46cvss 8.2epss 0.01
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the…
- risk 0.46cvss 7.1epss 0.01
Microsoft Authenticator Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.
- risk 0.46cvss 7.1epss 0.00
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
- risk 0.46cvss 7.0epss 0.00
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an…
- risk 0.46cvss 7.1epss 0.01
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
- risk 0.46cvss 8.1epss 0.01
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with…
- risk 0.46cvss 8.1epss 0.01
An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0
- risk 0.46cvss 7.1epss 0.00
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Administrative functions…
- risk 0.46cvss 7.1epss 0.00
In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue…
- risk 0.46cvss 8.1epss 0.01
An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in…
- risk 0.46cvss 7.1epss 0.00
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
- risk 0.46cvss 7.0epss 0.01
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit.
- risk 0.46cvss 8.1epss 0.02
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects…
- risk 0.46cvss 7.0epss 0.01
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.
- risk 0.46cvss 7.1epss 0.01
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo…
- risk 0.46cvss 7.1epss 0.01
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video…
- risk 0.46cvss 8.1epss 0.01
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed funds from user addresses. To do this an attacker must create a new chain which does not enforce signature verification and connects…