CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,835)
page 120 of 242| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30939 | Med | 0.44 | 6.8 | 0.00 | Apr 25, 2024 | An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory reset procedure. | ||
| CVE-2024-20803 | Med | 0.44 | 6.8 | 0.00 | Jan 4, 2024 | Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction. | ||
| CVE-2023-32661 | Med | 0.44 | 6.7 | 0.00 | Nov 14, 2023 | Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.19041.29098 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-28377 | Med | 0.44 | 6.7 | 0.00 | Nov 14, 2023 | Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2022-3916 | Med | 0.44 | 6.8 | 0.01 | Sep 20, 2023 | A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This… | ||
| CVE-2023-30560 | Med | 0.44 | 6.8 | 0.00 | Jul 13, 2023 | The configuration from the PCU can be modified without authentication using physical connection to the PCU. | ||
| CVE-2022-32570 | Med | 0.44 | 6.7 | 0.00 | Feb 16, 2023 | Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-20924 | Med | 0.44 | 6.8 | 0.00 | Jan 26, 2023 | In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege with physical access to the device with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-27874 | Med | 0.44 | 6.8 | 0.00 | Nov 11, 2022 | Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access. | ||
| CVE-2022-30124 | Med | 0.44 | 6.8 | 0.01 | Sep 23, 2022 | An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code). | ||
| CVE-2022-38399 | Med | 0.44 | 6.8 | 0.00 | Sep 8, 2022 | Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection | ||
| CVE-2022-29083 | Med | 0.44 | 6.8 | 0.00 | Aug 9, 2022 | Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system. | ||
| CVE-2022-30624 | Med | 0.44 | 6.8 | 0.00 | Jul 18, 2022 | Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password. | ||
| CVE-2022-22259 | Med | 0.44 | 6.8 | 0.00 | Jun 13, 2022 | There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device. | ||
| CVE-2022-31011 | Hig | 0.44 | 7.8 | 0.00 | May 31, 2022 | TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication process, resulting in privilege escalation or… | ||
| CVE-2022-26865 | Med | 0.44 | 6.8 | 0.00 | May 26, 2022 | Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the… | ||
| CVE-2021-42849 | Med | 0.44 | 6.8 | 0.00 | May 18, 2022 | A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access. | ||
| CVE-2021-46390 | Med | 0.44 | 6.8 | 0.00 | Mar 21, 2022 | An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and cause a Denial of Service (DoS). An attacker without access to securely protected data on a secure USB flash drive can bypass user authentication without… | ||
| CVE-2021-23147 | Med | 0.44 | 6.8 | 0.00 | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication. | ||
| CVE-2021-20168 | Med | 0.44 | 6.8 | 0.00 | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user.… |
- risk 0.44cvss 6.8epss 0.00
An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory reset procedure.
- risk 0.44cvss 6.8epss 0.00
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
- risk 0.44cvss 6.7epss 0.00
Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.19041.29098 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.44cvss 6.7epss 0.00
Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.44cvss 6.8epss 0.01
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This…
- risk 0.44cvss 6.8epss 0.00
The configuration from the PCU can be modified without authentication using physical connection to the PCU.
- risk 0.44cvss 6.7epss 0.00
Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.44cvss 6.8epss 0.00
In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege with physical access to the device with no additional execution privileges needed. User interaction is not needed for…
- risk 0.44cvss 6.8epss 0.00
Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access.
- risk 0.44cvss 6.8epss 0.01
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).
- risk 0.44cvss 6.8epss 0.00
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection
- risk 0.44cvss 6.8epss 0.00
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.
- risk 0.44cvss 6.8epss 0.00
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.
- risk 0.44cvss 6.8epss 0.00
There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device.
- risk 0.44cvss 7.8epss 0.00
TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication process, resulting in privilege escalation or…
- risk 0.44cvss 6.8epss 0.00
Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the…
- risk 0.44cvss 6.8epss 0.00
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
- risk 0.44cvss 6.8epss 0.00
An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and cause a Denial of Service (DoS). An attacker without access to securely protected data on a secure USB flash drive can bypass user authentication without…
- risk 0.44cvss 6.8epss 0.00
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication.
- risk 0.44cvss 6.8epss 0.00
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user.…