VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,835)

page 129 of 242
  • CVE-2022-48314MedApr 16, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-1980MedApr 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authentication via the application user interface and open entries.

  • CVE-2023-1460MedMar 17, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=save_user of the component Password Change Handler. The manipulation leads to improper authentication.…

  • CVE-2023-25931MedMar 1, 2023
    risk 0.42cvss 6.4epss 0.00

    Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy…

  • CVE-2023-21721MedFeb 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft OneNote Elevation of Privilege Vulnerability

  • CVE-2023-22497MedJan 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHINE GUID. It is generated when the agent first starts and it is saved to disk, so that it will persist across restarts and reboots.…

  • CVE-2023-0036MedJan 9, 2023
    risk 0.42cvss 6.5epss 0.00

    platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

  • CVE-2023-0035MedJan 9, 2023
    risk 0.42cvss 6.5epss 0.00

    softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

  • CVE-2022-47974MedJan 6, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth process to restart.

  • CVE-2022-23554MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as…

  • CVE-2022-41579MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.00

    There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect to the band.

  • CVE-2022-46172MedDec 28, 2022
    risk 0.42cvss 6.4epss 0.01

    authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where…

  • CVE-2022-46875MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108,…

  • CVE-2022-39901MedDec 8, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.

  • CVE-2022-22237MedOct 18, 2022
    risk 0.42cvss 6.5epss 0.00

    An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity. A vulnerability in the processing of TCP-AO will allow a BGP or LDP peer not configured with…

  • CVE-2022-2533MedOct 17, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP…

  • CVE-2021-40693MedSep 29, 2022
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

  • CVE-2022-39249HigSep 28, 2022
    risk 0.42cvss 7.5epss 0.01

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some…

  • CVE-2022-39246HigSep 28, 2022
    risk 0.42cvss 7.5epss 0.01

    matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be…

  • CVE-2022-36092HigSep 8, 2022
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.4, all rights checks that would normally prevent a user from viewing a document on a wiki can be bypassed using the login action and directly specified…