VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 114 of 253
  • CVE-2022-1101HigJan 7, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /royal_event/userregister.php. The manipulation leads to improper authentication. The attack may be initiated…

  • CVE-2022-3875HigDec 19, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affects unknown code of the component API. The manipulation leads to authentication bypass by assumed-immutable data. The attack can be…

  • CVE-2021-33159HigNov 11, 2022
    risk 0.48cvss 7.4epss 0.00

    Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-3465HigOct 12, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and…

  • CVE-2022-39290HigOct 7, 2022
    risk 0.48cvss 8.0epss 0.06

    ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. These modifications include replacing HTTP POST with an HTTP GET…

  • CVE-2022-36093HigSep 8, 2022
    risk 0.48cvss 8.5epss 0.01

    XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart template, user accounts can be created even when user registration is disabled. This also circumvents any email verification.…

  • CVE-2021-26638HigJun 23, 2022
    risk 0.48cvss 7.3epss 0.04

    Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control.

  • CVE-2022-1248HigApr 6, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin account for the web application with a simple…

  • CVE-2022-1084HigMar 29, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched…

  • CVE-2021-28503HigFeb 4, 2022
    risk 0.48cvss 7.4epss 0.01

    The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

  • CVE-2021-43355HigJan 21, 2022
    risk 0.48cvss 7.3epss 0.01

    Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript…

  • CVE-2021-23196HigJan 21, 2022
    risk 0.48cvss 7.3epss 0.01

    The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.

  • CVE-2021-27451HigDec 21, 2021
    risk 0.48cvss 7.3epss 0.01

    Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device.

  • CVE-2021-35964HigJul 19, 2021
    risk 0.48cvss 7.3epss 0.01

    The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users…

  • CVE-2021-1571HigJun 16, 2021
    risk 0.48cvss 7.2epss 0.10

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site…

  • CVE-2021-1543HigJun 16, 2021
    risk 0.48cvss 7.2epss 0.09

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site…

  • CVE-2021-1541HigJun 16, 2021
    risk 0.48cvss 7.2epss 0.09

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site…

  • CVE-2021-22171HigJan 15, 2021
    risk 0.48cvss 7.3epss 0.01

    Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

  • CVE-2020-11020HigApr 29, 2020
    risk 0.48cvss 8.5epss 0.02

    Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system. The vulnerability allows any client to bypass checks put in place by server-side extensions, by appending extra segments to the…

  • CVE-2020-8595HigFeb 12, 2020
    risk 0.48cvss 7.3epss 0.03

    Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting…