VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 139 of 255
  • CVE-2025-53845MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via crafted OFTP requests.

  • CVE-2025-59347MedSep 17, 2025
    risk 0.42cvss 6.5epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clients are not configurable, so users have no way to re-enable the verification. A Manager processes…

  • CVE-2025-54376HigSep 10, 2025
    risk 0.42cvss 7.5epss 0.01

    Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an unauthenticated remote attacker can stream…

  • CVE-2025-48746MedMay 28, 2025
    risk 0.42cvss 6.5epss 0.00

    Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.

  • CVE-2025-26685MedMay 13, 2025
    risk 0.42cvss 6.5epss 0.01

    Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

  • CVE-2025-25504MedMay 5, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.

  • CVE-2025-46630MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.

  • CVE-2025-30733MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS…

  • CVE-2025-24949MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In JotUrl 2.0, is possible to bypass security requirements during the password change process.

  • CVE-2025-30432MedMar 31, 2025
    risk 0.42cvss 6.4epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked…

  • CVE-2025-27422HigMar 3, 2025
    risk 0.42cvss 7.5epss 0.00

    FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing…

  • CVE-2024-13528HigFeb 12, 2025
    risk 0.42cvss 7.5epss 0.00

    The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it…

  • CVE-2023-52955MedJan 8, 2025
    risk 0.42cvss 6.5epss 0.00

    Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2025-21618HigJan 6, 2025
    risk 0.42cvss 7.5epss 0.00

    NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including browsers in incognito mode. This vulnerability is fixed in 2.9.1.

  • CVE-2024-36611HigNov 29, 2024
    risk 0.42cvss 7.5epss 0.01

    In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper…

  • CVE-2024-51996HigNov 13, 2024
    risk 0.42cvss 7.5epss 0.01

    Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to…

  • CVE-2024-10474MedOct 29, 2024
    risk 0.42cvss 6.5epss 0.00

    Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.

  • CVE-2024-49757HigOct 25, 2024
    risk 0.42cvss 7.5epss 0.03

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option…

  • CVE-2024-47127MedSep 26, 2024
    risk 0.42cvss 6.5epss 0.00

    In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted…

  • CVE-2024-5956MedSep 5, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly