VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 142 of 255
  • CVE-2022-23554MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as…

  • CVE-2022-41579MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.00

    There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect to the band.

  • CVE-2022-46172MedDec 28, 2022
    risk 0.42cvss 6.4epss 0.01

    authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where…

  • CVE-2022-46875MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108,…

  • CVE-2022-39901MedDec 8, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.

  • CVE-2022-22237MedOct 18, 2022
    risk 0.42cvss 6.5epss 0.00

    An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity. A vulnerability in the processing of TCP-AO will allow a BGP or LDP peer not configured with…

  • CVE-2022-2533MedOct 17, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP…

  • CVE-2021-40693MedSep 29, 2022
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

  • CVE-2022-39249HigSep 28, 2022
    risk 0.42cvss 7.5epss 0.01

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some…

  • CVE-2022-39246HigSep 28, 2022
    risk 0.42cvss 7.5epss 0.01

    matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be…

  • CVE-2022-36092HigSep 8, 2022
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.4, all rights checks that would normally prevent a user from viewing a document on a wiki can be bypassed using the login action and directly specified…

  • CVE-2021-3632HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

  • CVE-2021-3979MedAug 25, 2022
    risk 0.42cvss 6.5epss 0.01

    A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted…

  • CVE-2022-36296MedAug 5, 2022
    risk 0.42cvss 6.5epss 0.01

    Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.

  • CVE-2022-35142HigAug 4, 2022
    risk 0.42cvss 7.5epss 0.02

    An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.

  • CVE-2013-10004MedMay 24, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Password Handler. Incorrect implementation of a hashing…

  • CVE-2022-0910MedMay 24, 2022
    risk 0.42cvss 6.5epss 0.01

    A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN…

  • CVE-2022-24901HigMay 4, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks…

  • CVE-2022-23722MedMay 2, 2022
    risk 0.42cvss 6.5epss 0.01

    When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.

  • CVE-2021-3652MedApr 18, 2022
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user…