CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,804)
page 137 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5844 | Hig | 0.40 | 7.2 | 0.01 | Oct 30, 2023 | Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0. | ||
| CVE-2023-30675 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed. | ||
| CVE-2023-20199 | Med | 0.40 | 6.2 | 0.00 | Jun 28, 2023 | A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication and access an affected macOS device. This vulnerability is due to the incorrect handling of responses from Cisco Duo when the… | ||
| CVE-2023-23450 | Med | 0.40 | 6.2 | 0.01 | May 15, 2023 | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid… | ||
| CVE-2022-4722 | Hig | 0.40 | 7.2 | 0.01 | Dec 27, 2022 | Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5. | ||
| CVE-2022-45118 | Med | 0.40 | 6.2 | 0.00 | Dec 8, 2022 | OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data… | ||
| CVE-2022-20662 | Med | 0.40 | 6.1 | 0.00 | Sep 30, 2022 | A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability exists because the assigned user of a smart card is not properly matched with the… | ||
| CVE-2022-38081 | Med | 0.40 | 6.2 | 0.00 | Sep 9, 2022 | OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system. | ||
| CVE-2022-38064 | Med | 0.40 | 6.2 | 0.00 | Sep 9, 2022 | OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information. | ||
| CVE-2022-26858 | Med | 0.40 | 6.1 | 0.00 | Sep 6, 2022 | Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls. | ||
| CVE-2022-33732 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call. | ||
| CVE-2022-33689 | Med | 0.40 | 6.2 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call. | ||
| CVE-2022-25825 | Med | 0.40 | 6.2 | 0.00 | Mar 10, 2022 | Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in. | ||
| CVE-2021-36718 | Med | 0.40 | 6.1 | 0.01 | Dec 8, 2021 | SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11.… | ||
| CVE-2021-3458 | Med | 0.40 | 6.1 | 0.00 | Aug 17, 2021 | The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified. | ||
| CVE-2021-20288 | Hig | 0.40 | 7.2 | 0.02 | Apr 15, 2021 | An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a… | ||
| CVE-2019-15615 | Med | 0.40 | 6.1 | 0.00 | Feb 4, 2020 | A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past. | ||
| CVE-2013-5114 | Med | 0.40 | 6.1 | 0.01 | Jan 31, 2020 | LastPass prior to 2.5.1 allows secure wipe bypass. | ||
| CVE-2019-5453 | Med | 0.40 | 6.1 | 0.00 | Jul 30, 2019 | Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider. | ||
| CVE-2018-7940 | Med | 0.40 | 6.2 | 0.00 | May 10, 2018 | Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some… |
- risk 0.40cvss 7.2epss 0.01
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
- risk 0.40cvss 6.2epss 0.00
Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.
- risk 0.40cvss 6.2epss 0.00
A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication and access an affected macOS device. This vulnerability is due to the incorrect handling of responses from Cisco Duo when the…
- risk 0.40cvss 6.2epss 0.01
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid…
- risk 0.40cvss 7.2epss 0.01
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.40cvss 6.2epss 0.00
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data…
- risk 0.40cvss 6.1epss 0.00
A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability exists because the assigned user of a smart card is not properly matched with the…
- risk 0.40cvss 6.2epss 0.00
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
- risk 0.40cvss 6.2epss 0.00
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
- risk 0.40cvss 6.1epss 0.00
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.
- risk 0.40cvss 6.1epss 0.01
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11.…
- risk 0.40cvss 6.1epss 0.00
The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.
- risk 0.40cvss 7.2epss 0.02
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a…
- risk 0.40cvss 6.1epss 0.00
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
- risk 0.40cvss 6.1epss 0.01
LastPass prior to 2.5.1 allows secure wipe bypass.
- risk 0.40cvss 6.1epss 0.00
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
- risk 0.40cvss 6.2epss 0.00
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some…