VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 132 of 255
  • CVE-2021-46390MedMar 21, 2022
    risk 0.44cvss 6.8epss 0.00

    An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and cause a Denial of Service (DoS). An attacker without access to securely protected data on a secure USB flash drive can bypass user authentication without…

  • CVE-2021-23147MedDec 30, 2021
    risk 0.44cvss 6.8epss 0.00

    Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication.

  • CVE-2021-20168MedDec 30, 2021
    risk 0.44cvss 6.8epss 0.00

    Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user.…

  • CVE-2021-20161MedDec 30, 2021
    risk 0.44cvss 6.8epss 0.00

    Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection. No username or password is required and the user is given…

  • CVE-2021-3788MedNov 12, 2021
    risk 0.44cvss 6.8epss 0.00

    An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.

  • CVE-2021-3145MedSep 10, 2021
    risk 0.44cvss 6.7epss 0.01

    In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.

  • CVE-2021-3046MedAug 11, 2021
    risk 0.44cvss 6.8epss 0.01

    An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication. This issue…

  • CVE-2021-32794MedJul 26, 2021
    risk 0.44cvss 6.8epss 0.01

    ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /Api/ASF` ASF API endpoint responsible for updating global ASF config incorrectly removed `IPCPassword` from the resulting config…

  • CVE-2021-34546MedJun 10, 2021
    risk 0.44cvss 6.8epss 0.01

    An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via…

  • CVE-2020-24514MedJun 9, 2021
    risk 0.44cvss 6.8epss 0.00

    Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

  • CVE-2021-31924MedMay 26, 2021
    risk 0.44cvss 6.8epss 0.00

    Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, so an attacker would…

  • CVE-2019-5317MedMar 29, 2021
    risk 0.44cvss 6.8epss 0.00

    A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba Instant 8.3.x: 8.3.0.11 and below; Aruba Instant 8.4.x:…

  • CVE-2020-26200MedFeb 26, 2021
    risk 0.44cvss 6.8epss 0.00

    A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky…

  • CVE-2020-8236MedNov 2, 2020
    risk 0.44cvss 6.8epss 0.01

    A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

  • CVE-2020-3151MedAug 26, 2020
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the CLI of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to bypass restrictions on the CLI. The vulnerability is due to insufficient security mechanisms in the restricted shell…

  • CVE-2020-24612MedAug 24, 2020
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If…

  • CVE-2020-12638MedJul 23, 2020
    risk 0.44cvss 6.8epss 0.00

    An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively…

  • CVE-2020-9076MedJun 15, 2020
    risk 0.44cvss 6.8epss 0.01

    HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not…

  • CVE-2020-3216MedJun 3, 2020
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication…

  • CVE-2020-10847MedMar 24, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SVE-2019-16614 (February 2020).