VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 143 of 255
  • CVE-2022-1067MedApr 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting.

  • CVE-2021-45900MedMar 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed without proper…

  • CVE-2022-0996MedMar 23, 2022
    risk 0.42cvss 6.5epss 0.02

    A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.

  • CVE-2022-23635HigFeb 22, 2022
    risk 0.42cvss 7.5epss 0.02

    Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane…

  • CVE-2021-38679MedFeb 11, 2022
    risk 0.42cvss 6.5epss 0.01

    An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Kazoo Server:…

  • CVE-2021-40404MedJan 28, 2022
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-3519MedNov 12, 2021
    risk 0.42cvss 6.4epss 0.00

    A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.

  • CVE-2021-39872MedOct 5, 2021
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

  • CVE-2021-31606HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.03

    furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.

  • CVE-2021-25466MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.

  • CVE-2021-34786MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.

  • CVE-2021-34785MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.

  • CVE-2021-22004MedSep 8, 2021
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion…

  • CVE-2021-20737MedJun 22, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.

  • CVE-2020-26136MedJun 8, 2021
    risk 0.42cvss 6.5epss 0.01

    In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.

  • CVE-2021-32543MedMay 28, 2021
    risk 0.42cvss 6.5epss 0.01

    The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity.

  • CVE-2021-26074MedApr 16, 2021
    risk 0.42cvss 6.5epss 0.01

    Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot…

  • CVE-2021-28174MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.01

    Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can gain the privileged permissions to access transaction record, and fraudulent trading without login.

  • CVE-2021-21403HigMar 26, 2021
    risk 0.42cvss 7.5epss 0.01

    In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21.

  • CVE-2021-3153MedMar 26, 2021
    risk 0.42cvss 6.5epss 0.01

    HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.