VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 114 of 241
  • CVE-2024-34103HigJun 13, 2024
    risk 0.46cvss 8.1epss 0.01

    Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the…

  • CVE-2024-22257HigMar 18, 2024
    risk 0.46cvss 8.2epss 0.01

    In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control when it directly uses the…

  • CVE-2024-21390HigMar 12, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft Authenticator Elevation of Privilege Vulnerability

  • CVE-2022-41737HigFeb 17, 2024
    risk 0.46cvss 7.1epss 0.00

    IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.

  • CVE-2023-33070HigDec 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Transient DOS in Automotive OS due to improper authentication to the secure IO calls.

  • CVE-2023-4677HigNov 23, 2023
    risk 0.46cvss 7.0epss 0.00

    Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an…

  • CVE-2023-39215HigSep 12, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-21626HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.

  • CVE-2023-39349HigAug 7, 2023
    risk 0.46cvss 8.1epss 0.01

    Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with…

  • CVE-2023-29032HigMay 12, 2023
    risk 0.46cvss 8.1epss 0.01

    An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0

  • CVE-2023-28973HigApr 17, 2023
    risk 0.46cvss 7.1epss 0.00

    An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system availability. Administrative functions…

  • CVE-2021-40342HigJan 5, 2023
    risk 0.46cvss 7.1epss 0.00

    In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue…

  • CVE-2022-47633HigDec 23, 2022
    risk 0.46cvss 8.1epss 0.01

    An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in…

  • CVE-2022-46829HigDec 8, 2022
    risk 0.46cvss 7.1epss 0.00

    In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.

  • CVE-2022-26870HigOct 21, 2022
    risk 0.46cvss 7.0epss 0.01

    Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit.

  • CVE-2022-22576HigMay 26, 2022
    risk 0.46cvss 8.1epss 0.02

    An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects…

  • CVE-2022-22796HigMay 12, 2022
    risk 0.46cvss 7.0epss 0.01

    Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.

  • CVE-2021-44057HigMay 5, 2022
    risk 0.46cvss 7.1epss 0.01

    An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo…

  • CVE-2021-44056HigMay 5, 2022
    risk 0.46cvss 7.1epss 0.01

    An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video…

  • CVE-2022-24738HigMar 7, 2022
    risk 0.46cvss 8.1epss 0.01

    Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed funds from user addresses. To do this an attacker must create a new chain which does not enforce signature verification and connects…