VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 144 of 241
  • CVE-2023-42935MedJan 23, 2024
    risk 0.36cvss 5.5epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.

  • CVE-2023-7211MedJan 7, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipulation leads to reliance on ip address for authentication. The attack can be initiated remotely. The…

  • CVE-2023-31292MedDec 29, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.

  • CVE-2023-43582MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

  • CVE-2023-26455MedNov 2, 2023
    risk 0.36cvss 5.6epss 0.00

    RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated…

  • CVE-2023-36724MedOct 10, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Power Management Service Information Disclosure Vulnerability

  • CVE-2023-41751MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before build 32047.

  • CVE-2023-27538MedMar 30, 2023
    risk 0.36cvss 5.5epss 0.01

    An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse…

  • CVE-2022-48305MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail.

  • CVE-2022-33946MedFeb 16, 2023
    risk 0.36cvss 5.6epss 0.00

    Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-43978MedJan 27, 2023
    risk 0.36cvss 5.6epss 0.00

    There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can…

  • CVE-2022-41590MedDec 20, 2022
    risk 0.36cvss 5.5epss 0.00

    Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.

  • CVE-2022-2752MedDec 9, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

  • CVE-2022-34331MedNov 11, 2022
    risk 0.36cvss 5.5epss 0.00

    After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.

  • CVE-2020-36528MedJun 7, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken access control. The attack requires authentication. Upgrading to version 1.0.4.851 is able to address this issue. It is recommended to…

  • CVE-2022-26724MedMay 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication.

  • CVE-2021-33087MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2010-2496MedOct 18, 2021
    risk 0.36cvss 5.5epss 0.00

    stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3…

  • CVE-2021-30770MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

  • CVE-2021-30769MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.