CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,090)
page 143 of 255| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1067 | Med | 0.42 | 6.5 | 0.01 | Apr 11, 2022 | Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting. | ||
| CVE-2021-45900 | Med | 0.42 | 6.5 | 0.01 | Mar 30, 2022 | Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed without proper… | ||
| CVE-2022-0996 | Med | 0.42 | 6.5 | 0.02 | Mar 23, 2022 | A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. | ||
| CVE-2022-23635 | Hig | 0.42 | 7.5 | 0.02 | Feb 22, 2022 | Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane… | ||
| CVE-2021-38679 | Med | 0.42 | 6.5 | 0.01 | Feb 11, 2022 | An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Kazoo Server:… | ||
| CVE-2021-40404 | Med | 0.42 | 6.5 | 0.01 | Jan 28, 2022 | An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability. | ||
| CVE-2021-3519 | Med | 0.42 | 6.4 | 0.00 | Nov 12, 2021 | A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes. | ||
| CVE-2021-39872 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration. | ||
| CVE-2021-31606 | Hig | 0.42 | 7.5 | 0.03 | Sep 27, 2021 | furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients. | ||
| CVE-2021-25466 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2021 | Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token. | ||
| CVE-2021-34786 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2021 | Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. | ||
| CVE-2021-34785 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2021 | Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. | ||
| CVE-2021-22004 | Med | 0.42 | 6.4 | 0.00 | Sep 8, 2021 | An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion… | ||
| CVE-2021-20737 | Med | 0.42 | 6.5 | 0.01 | Jun 22, 2021 | Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors. | ||
| CVE-2020-26136 | Med | 0.42 | 6.5 | 0.01 | Jun 8, 2021 | In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication. | ||
| CVE-2021-32543 | Med | 0.42 | 6.5 | 0.01 | May 28, 2021 | The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity. | ||
| CVE-2021-26074 | Med | 0.42 | 6.5 | 0.01 | Apr 16, 2021 | Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot… | ||
| CVE-2021-28174 | Med | 0.42 | 6.5 | 0.01 | Apr 8, 2021 | Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can gain the privileged permissions to access transaction record, and fraudulent trading without login. | ||
| CVE-2021-21403 | Hig | 0.42 | 7.5 | 0.01 | Mar 26, 2021 | In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21. | ||
| CVE-2021-3153 | Med | 0.42 | 6.5 | 0.01 | Mar 26, 2021 | HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1. |
- risk 0.42cvss 6.5epss 0.01
Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting.
- risk 0.42cvss 6.5epss 0.01
Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed without proper…
- risk 0.42cvss 6.5epss 0.02
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
- risk 0.42cvss 7.5epss 0.02
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane…
- risk 0.42cvss 6.5epss 0.01
An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Kazoo Server:…
- risk 0.42cvss 6.5epss 0.01
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.
- risk 0.42cvss 6.4epss 0.00
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
- risk 0.42cvss 7.5epss 0.03
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
- risk 0.42cvss 6.5epss 0.01
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
- risk 0.42cvss 6.5epss 0.01
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
- risk 0.42cvss 6.5epss 0.01
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
- risk 0.42cvss 6.4epss 0.00
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion…
- risk 0.42cvss 6.5epss 0.01
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
- risk 0.42cvss 6.5epss 0.01
The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity.
- risk 0.42cvss 6.5epss 0.01
Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot…
- risk 0.42cvss 6.5epss 0.01
Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can gain the privileged permissions to access transaction record, and fraudulent trading without login.
- risk 0.42cvss 7.5epss 0.01
In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21.
- risk 0.42cvss 6.5epss 0.01
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.