VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 140 of 255
  • CVE-2024-7745MedAug 28, 2024
    risk 0.42cvss 6.5epss 0.00

    In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

  • CVE-2024-38810MedAug 20, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

  • CVE-2024-25157MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.

  • CVE-2024-34788MedAug 7, 2024
    risk 0.42cvss 6.5epss 0.01

    An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

  • CVE-2024-38523HigJun 27, 2024
    risk 0.42cvss 7.5epss 0.01

    Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issues that weakens its one-time nature. Specifically, the lack of 2FA for changing security settings allows attacker with CSRF or XSS…

  • CVE-2022-45168MedJun 10, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate…

  • CVE-2023-51511MedJun 4, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.3.

  • CVE-2023-48747MedJun 4, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster for WooCommerce: from n/a through 7.1.2.

  • CVE-2023-6787MedApr 25, 2024
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the…

  • CVE-2023-47504MedApr 24, 2024
    risk 0.42cvss 6.5epss 0.01

    Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.

  • CVE-2023-48865MedApr 11, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.

  • CVE-2023-38367MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an…

  • CVE-2023-52160MedFeb 22, 2024
    risk 0.42cvss 6.5epss 0.01

    The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused…

  • CVE-2023-46942HigJan 13, 2024
    risk 0.42cvss 7.5epss 0.01

    Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

  • CVE-2023-37544HigDec 20, 2023
    risk 0.42cvss 7.5epss 0.01

    Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2.10.0 through…

  • CVE-2023-49646MedDec 13, 2023
    risk 0.42cvss 6.4epss 0.00

    Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-50430MedDec 9, 2023
    risk 0.42cvss 6.4epss 0.00

    The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of…

  • CVE-2023-34388MedNov 30, 2023
    risk 0.42cvss 6.5epss 0.01

    An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instruction Manual Appendix A dated 20230830 for…

  • CVE-2022-3681MedOct 27, 2023
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

  • CVE-2023-43809HigOct 4, 2023
    risk 0.42cvss 7.5epss 0.01

    Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to bypass public key authentication when keyboard-interactive SSH authentication is active, through the…