VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 122 of 255
  • CVE-2023-29975HigNov 9, 2023
    risk 0.47cvss 7.2epss 0.02

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

  • CVE-2023-36815HigJul 3, 2023
    risk 0.47cvss 7.3epss 0.01

    Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the…

  • CVE-2023-35154HigJun 23, 2023
    risk 0.47cvss 7.2epss 0.00

    Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allowing them access to the application as a…

  • CVE-2023-1477HigApr 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.

  • CVE-2023-27091HigApr 4, 2023
    risk 0.47cvss 7.2epss 0.01

    An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).

  • CVE-2022-37931HigNov 22, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.

  • CVE-2022-3674HigOct 26, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The identifier…

  • CVE-2022-35203HigAug 23, 2022
    risk 0.47cvss 7.2epss 0.01

    An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.

  • CVE-2022-2664HigAug 5, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It…

  • CVE-2022-30755HigJul 12, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.

  • CVE-2022-30229HigJun 14, 2022
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case…

  • CVE-2021-30028HigMay 20, 2022
    risk 0.47cvss 7.2epss 0.01

    SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.

  • CVE-2021-0193HigMay 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2020-25719HigFeb 18, 2022
    risk 0.47cvss 7.2epss 0.02

    A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found…

  • CVE-2021-41126HigOct 6, 2021
    risk 0.47cvss 7.2epss 0.01

    October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versions administrator accounts which had previously been deleted may still be able to sign in to the backend using October CMS v2.0. The issue has been patched in…

  • CVE-2021-28495HigSep 9, 2021
    risk 0.47cvss 7.2epss 0.01

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in…

  • CVE-2021-33539HigJun 25, 2021
    risk 0.47cvss 7.2epss 0.01

    In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a…

  • CVE-2021-1542HigJun 16, 2021
    risk 0.47cvss 7.2epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site…

  • CVE-2021-26070HigMar 22, 2021
    risk 0.47cvss 7.2epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and…

  • CVE-2020-16251HigAug 26, 2020
    risk 0.47cvss 8.2epss 0.03

    HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.