VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 141 of 255
  • CVE-2023-4094MedSep 19, 2023
    risk 0.42cvss 6.5epss 0.01

    ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the…

  • CVE-2023-32202MedAug 23, 2023
    risk 0.42cvss 6.5epss 0.01

    Walchem Intuition 9 firmware versions prior to v4.21 are vulnerable to improper authentication. Login credentials are stored in a format that could allow an attacker to use them as-is to login and gain access to the device.

  • CVE-2023-39531MedAug 9, 2023
    risk 0.42cvss 6.5epss 0.00

    Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2, an attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect…

  • CVE-2023-39112MedAug 4, 2023
    risk 0.42cvss 6.5epss 0.01

    ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.

  • CVE-2023-32620MedJun 30, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attacker to obtain a password for the wireless network.

  • CVE-2023-34367MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor considers this a…

  • CVE-2023-2283MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The…

  • CVE-2023-28325MedMay 11, 2023
    risk 0.42cvss 6.5epss 0.00

    An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.

  • CVE-2023-28182MedMay 8, 2023
    risk 0.42cvss 6.5epss 0.01

    The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A user in a privileged network position may be able to spoof a VPN server that is…

  • CVE-2022-40723MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.01

    The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.

  • CVE-2023-22893HigApr 19, 2023
    risk 0.42cvss 7.5epss 0.04

    Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and…

  • CVE-2022-48314MedApr 16, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-1980MedApr 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authentication via the application user interface and open entries.

  • CVE-2023-1460MedMar 17, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=save_user of the component Password Change Handler. The manipulation leads to improper authentication.…

  • CVE-2023-25931MedMar 1, 2023
    risk 0.42cvss 6.4epss 0.00

    Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy…

  • CVE-2023-21721MedFeb 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft OneNote Elevation of Privilege Vulnerability

  • CVE-2023-22497MedJan 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHINE GUID. It is generated when the agent first starts and it is saved to disk, so that it will persist across restarts and reboots.…

  • CVE-2023-0036MedJan 9, 2023
    risk 0.42cvss 6.5epss 0.00

    platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

  • CVE-2023-0035MedJan 9, 2023
    risk 0.42cvss 6.5epss 0.00

    softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

  • CVE-2022-47974MedJan 6, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth process to restart.