VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 140 of 241
  • CVE-2023-38372MedFeb 29, 2024
    risk 0.38cvss 5.9epss 0.01

    An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM X-Force ID: 261201.

  • CVE-2023-50127MedJan 11, 2024
    risk 0.38cvss 5.9epss 0.00

    Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a disarmed state from any given phone number.

  • CVE-2023-22663MedNov 14, 2023
    risk 0.38cvss 5.9epss 0.01

    Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-46327MedNov 2, 2023
    risk 0.38cvss 5.9epss 0.00

    Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption…

  • CVE-2023-4985MedSep 15, 2023
    risk 0.38cvss 5.9epss 0.00

    A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml. The manipulation leads to improper authentication. An attack has to be approached locally. The exploit has been disclosed to the…

  • CVE-2023-2638MedJun 13, 2023
    risk 0.38cvss 5.9epss 0.00

    Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local,…

  • CVE-2023-20867LowKEVJun 13, 2023
    risk 0.38cvss 3.9epss 0.14

    A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

  • CVE-2023-25597MedApr 14, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentication control. A successful exploit…

  • CVE-2023-27536MedMar 30, 2023
    risk 0.38cvss 5.9epss 0.02

    An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability…

  • CVE-2023-27535MedMar 30, 2023
    risk 0.38cvss 5.9epss 0.02

    An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current…

  • CVE-2023-21455MedMar 16, 2023
    risk 0.38cvss 5.9epss 0.00

    Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.

  • CVE-2022-4041MedJan 31, 2023
    risk 0.38cvss 5.9epss 0.01

    Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.1.

  • CVE-2022-35646MedDec 22, 2022
    risk 0.38cvss 5.9epss 0.00

    IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.  

  • CVE-2022-34839MedJul 22, 2022
    risk 0.38cvss 5.9epss 0.01

    Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.

  • CVE-2022-30623MedJul 18, 2022
    risk 0.38cvss 5.9epss 0.00

    The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.

  • CVE-2020-36548MedJun 17, 2022
    risk 0.38cvss 5.9epss 0.00

    A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibilities. It is possible to launch the attack on the local host.

  • CVE-2021-36350MedDec 21, 2021
    risk 0.38cvss 5.9epss 0.01

    Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote unauthenticated attacker may potentially exploit this vulnerability and bypass one of the factors of authentication.

  • CVE-2020-10254MedFeb 19, 2021
    risk 0.38cvss 5.9epss 0.02

    An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.

  • CVE-2020-3565MedOct 21, 2020
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices on an affected system. The vulnerability…

  • CVE-2019-15993MedSep 23, 2020
    risk 0.38cvss 5.3epss 0.10

    A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An…