VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,835)

page 130 of 242
  • CVE-2021-3632HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

  • CVE-2022-36296MedAug 5, 2022
    risk 0.42cvss 6.5epss 0.01

    Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.

  • CVE-2022-35142HigAug 4, 2022
    risk 0.42cvss 7.5epss 0.02

    An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.

  • CVE-2013-10004MedMay 24, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Password Handler. Incorrect implementation of a hashing…

  • CVE-2022-0910MedMay 24, 2022
    risk 0.42cvss 6.5epss 0.01

    A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN…

  • CVE-2022-24901HigMay 4, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks…

  • CVE-2022-23722MedMay 2, 2022
    risk 0.42cvss 6.5epss 0.01

    When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.

  • CVE-2021-3652MedApr 18, 2022
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user…

  • CVE-2022-1067MedApr 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting.

  • CVE-2021-45900MedMar 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed without proper…

  • CVE-2022-0996MedMar 23, 2022
    risk 0.42cvss 6.5epss 0.02

    A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.

  • CVE-2022-23635HigFeb 22, 2022
    risk 0.42cvss 7.5epss 0.02

    Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane…

  • CVE-2021-38679MedFeb 11, 2022
    risk 0.42cvss 6.5epss 0.01

    An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Kazoo Server:…

  • CVE-2021-40404MedJan 28, 2022
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-3519MedNov 12, 2021
    risk 0.42cvss 6.4epss 0.00

    A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.

  • CVE-2021-39872MedOct 5, 2021
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

  • CVE-2021-31606HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.03

    furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.

  • CVE-2021-25466MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.

  • CVE-2021-34786MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.

  • CVE-2021-34785MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.