VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,835)

page 123 of 242
  • CVE-2017-15351MedFeb 15, 2018
    risk 0.44cvss 6.8epss 0.00

    The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerability. Due to improper authentication realization in the 'Find Phone' function. An attacker may exploit the vulnerability to bypass…

  • CVE-2017-16858MedJan 31, 2018
    risk 0.44cvss 6.8epss 0.01

    The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a directory bound to an application using…

  • CVE-2017-8151MedNov 22, 2017
    risk 0.44cvss 6.8epss 0.00

    Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design of some components. An attacker can get a user's smart phone and install malicious apps in the mobile phone, allowing the…

  • CVE-2017-10709MedJun 30, 2017
    risk 0.44cvss 6.8epss 0.00

    The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.

  • CVE-2017-8879MedMay 10, 2017
    risk 0.44cvss 6.8epss 0.00

    Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.

  • CVE-2016-4484MedJan 23, 2017
    risk 0.44cvss 6.8epss 0.01

    The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.

  • CVE-2014-2005MedJun 25, 2014
    risk 0.44cvss 6.8epss 0.01

    Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a…

  • CVE-2026-53514HigJul 15, 2026
    risk 0.43cvss 7.7epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin's…

  • CVE-2026-58423HigJul 3, 2026
    risk 0.43cvss 7.7epss 0.00

    LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

  • CVE-2025-46641MedApr 17, 2026
    risk 0.43cvss 6.6epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2025-46607MedApr 17, 2026
    risk 0.43cvss 6.6epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-5959MedApr 9, 2026
    risk 0.43cvss 6.6epss 0.01

    A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory Reset Handler. Performing a manipulation results in improper authentication. The attack can be initiated…

  • CVE-2026-32064HigMar 21, 2026
    risk 0.43cvss 7.7epss 0.01

    OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to…

  • CVE-2025-46631MedMay 1, 2025
    risk 0.43cvss 6.5epss 0.07

    Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.

  • CVE-2024-52280HigApr 11, 2025
    risk 0.43cvss 7.7epss 0.00

    A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch resources they are not allowed to access, when they have at least some generic permissions on the type. This issue affects rancher: before 2175e09, before…

  • CVE-2025-3062MedMar 31, 2025
    risk 0.43cvss 6.6epss 0.00

    Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.

  • CVE-2025-3061MedMar 31, 2025
    risk 0.43cvss 6.6epss 0.00

    Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.

  • CVE-2024-9133MedJan 10, 2025
    risk 0.43cvss 6.6epss 0.00

    A user with administrator privileges is able to retrieve authentication tokens

  • CVE-2023-40660MedNov 6, 2023
    risk 0.43cvss 6.6epss 0.01

    A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS…

  • CVE-2023-31015MedSep 20, 2023
    risk 0.43cvss 6.6epss 0.00

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, code execution, and denial of service.