VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,835)

page 121 of 242
  • CVE-2021-20161MedDec 30, 2021
    risk 0.44cvss 6.8epss 0.00

    Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection. No username or password is required and the user is given…

  • CVE-2021-3788MedNov 12, 2021
    risk 0.44cvss 6.8epss 0.00

    An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.

  • CVE-2021-3145MedSep 10, 2021
    risk 0.44cvss 6.7epss 0.01

    In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.

  • CVE-2021-3046MedAug 11, 2021
    risk 0.44cvss 6.8epss 0.01

    An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication. This issue…

  • CVE-2021-34546MedJun 10, 2021
    risk 0.44cvss 6.8epss 0.01

    An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via…

  • CVE-2020-24514MedJun 9, 2021
    risk 0.44cvss 6.8epss 0.00

    Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

  • CVE-2021-31924MedMay 26, 2021
    risk 0.44cvss 6.8epss 0.00

    Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, so an attacker would…

  • CVE-2019-5317MedMar 29, 2021
    risk 0.44cvss 6.8epss 0.00

    A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba Instant 8.3.x: 8.3.0.11 and below; Aruba Instant 8.4.x:…

  • CVE-2020-26200MedFeb 26, 2021
    risk 0.44cvss 6.8epss 0.00

    A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky…

  • CVE-2020-8236MedNov 2, 2020
    risk 0.44cvss 6.8epss 0.01

    A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

  • CVE-2020-3151MedAug 26, 2020
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the CLI of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to bypass restrictions on the CLI. The vulnerability is due to insufficient security mechanisms in the restricted shell…

  • CVE-2020-12638MedJul 23, 2020
    risk 0.44cvss 6.8epss 0.00

    An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively…

  • CVE-2020-9076MedJun 15, 2020
    risk 0.44cvss 6.8epss 0.01

    HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not…

  • CVE-2020-3216MedJun 3, 2020
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication…

  • CVE-2020-10847MedMar 24, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SVE-2019-16614 (February 2020).

  • CVE-2020-8994MedMar 5, 2020
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then they can read Wi-Fi SSID or password, read the dialogue text files between users and XIAOMI AI speaker, use Text-To-Speech tools…

  • CVE-2020-1842MedFeb 18, 2020
    risk 0.44cvss 6.8epss 0.00

    Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker can access the device physically and perform specific operations to exploit this…

  • CVE-2020-1789MedFeb 18, 2020
    risk 0.44cvss 6.8epss 0.00

    Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentication vulnerability. The software does not require a strong credential when the user trying to do certain operations. Successful exploit could allow an…

  • CVE-2019-14598MedFeb 13, 2020
    risk 0.44cvss 6.7epss 0.00

    Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information…

  • CVE-2019-8760MedDec 18, 2019
    risk 0.44cvss 6.8epss 0.00

    This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.