VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 139 of 241
  • CVE-2018-7108MedSep 27, 2018
    risk 0.39cvss 5.9epss 0.02

    HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system. This problem sometimes occurred under specific…

  • CVE-2017-7934MedAug 25, 2017
    risk 0.39cvss 5.9epss 0.02

    An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a malicious user to authenticate with a server and then cause PI Network Manager to…

  • CVE-2017-8006MedJul 17, 2017
    risk 0.39cvss 5.9epss 0.02

    In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the…

  • CVE-2026-65329MedAug 17, 2026
    risk 0.38cvss 5.9epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.

  • CVE-2026-35511higAug 14, 2026
    risk 0.38cvss epss

    The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account's email was verified by its original owner. An attacker who pre-registers with a victim's email address…

  • CVE-2026-16739MedAug 14, 2026
    risk 0.38cvss 5.9epss 0.00

    The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as…

  • CVE-2026-15087MedJul 10, 2026
    risk 0.38cvss 5.9epss 0.00

    vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.

  • CVE-2023-5502MedJun 4, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.

  • CVE-2026-40178MedApr 10, 2026
    risk 0.38cvss 5.9epss 0.00

    ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112.

  • CVE-2025-6723MedJan 30, 2026
    risk 0.38cvss epss 0.00

    Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may interfere with the pipe connection process and exploit the insufficient access restrictions to assume the InSpec execution context,…

  • CVE-2025-53545MedJul 8, 2025
    risk 0.38cvss epss 0.00

    Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can circumvent 2FA login for users due to a lack of server side validation for the same. This vulnerability is fixed in commit…

  • CVE-2024-7487MedMay 22, 2025
    risk 0.38cvss 5.8epss 0.00

    An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malicious actors to circumvent the…

  • CVE-2024-44843MedApr 15, 2025
    risk 0.38cvss 5.9epss 0.00

    An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.

  • CVE-2025-30168MedMar 21, 2025
    risk 0.38cvss 6.9epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authentication handling of Parse Server allows the authentication credentials of some specific authentication providers to be used…

  • CVE-2025-27416MedMar 1, 2025
    risk 0.38cvss epss 0.00

    Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with scratch username and password form. Any user who used the sign in page would be susceptible to any other user signing into their account. As of time of…

  • CVE-2024-35775MedAug 12, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vulnerability in Soliloquy Team Slider by Soliloquy allows Cross-Site Scripting (XSS).This issue affects Slider by Soliloquy: from n/a through 2.7.6.

  • CVE-2024-38099MedJul 9, 2024
    risk 0.38cvss 5.9epss 0.01

    Windows Remote Desktop Licensing Service Denial of Service Vulnerability

  • CVE-2024-34596MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.

  • CVE-2024-20889MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.

  • CVE-2024-2112MedApr 9, 2024
    risk 0.38cvss 5.9epss 0.01

    The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible for unauthenticated attackers…