CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,804)
page 144 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42935 | Med | 0.36 | 5.5 | 0.00 | Jan 23, 2024 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen. | ||
| CVE-2023-7211 | Med | 0.36 | 5.6 | 0.01 | Jan 7, 2024 | A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipulation leads to reliance on ip address for authentication. The attack can be initiated remotely. The… | ||
| CVE-2023-31292 | Med | 0.36 | 5.5 | 0.00 | Dec 29, 2023 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack. | ||
| CVE-2023-43582 | Med | 0.36 | 5.5 | 0.01 | Nov 15, 2023 | Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. | ||
| CVE-2023-26455 | Med | 0.36 | 5.6 | 0.00 | Nov 2, 2023 | RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated… | ||
| CVE-2023-36724 | Med | 0.36 | 5.5 | 0.01 | Oct 10, 2023 | Windows Power Management Service Information Disclosure Vulnerability | ||
| CVE-2023-41751 | Med | 0.36 | 5.5 | 0.00 | Aug 31, 2023 | Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before build 32047. | ||
| CVE-2023-27538 | Med | 0.36 | 5.5 | 0.01 | Mar 30, 2023 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse… | ||
| CVE-2022-48305 | Med | 0.36 | 5.5 | 0.00 | Feb 27, 2023 | There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail. | ||
| CVE-2022-33946 | Med | 0.36 | 5.6 | 0.00 | Feb 16, 2023 | Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2022-43978 | Med | 0.36 | 5.6 | 0.00 | Jan 27, 2023 | There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can… | ||
| CVE-2022-41590 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2022 | Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability. | ||
| CVE-2022-2752 | Med | 0.36 | 5.5 | 0.00 | Dec 9, 2022 | A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7. | ||
| CVE-2022-34331 | Med | 0.36 | 5.5 | 0.00 | Nov 11, 2022 | After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695. | ||
| CVE-2020-36528 | Med | 0.36 | 5.5 | 0.01 | Jun 7, 2022 | A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken access control. The attack requires authentication. Upgrading to version 1.0.4.851 is able to address this issue. It is recommended to… | ||
| CVE-2022-26724 | Med | 0.36 | 5.5 | 0.00 | May 26, 2022 | An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication. | ||
| CVE-2021-33087 | Med | 0.36 | 5.5 | 0.00 | Nov 17, 2021 | Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2010-2496 | Med | 0.36 | 5.5 | 0.00 | Oct 18, 2021 | stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3… | ||
| CVE-2021-30770 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2021 | A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations. | ||
| CVE-2021-30769 | Med | 0.36 | 5.5 | 0.01 | Sep 8, 2021 | A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. |
- risk 0.36cvss 5.5epss 0.00
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.
- risk 0.36cvss 5.6epss 0.01
A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipulation leads to reliance on ip address for authentication. The attack can be initiated remotely. The…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.
- risk 0.36cvss 5.5epss 0.01
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
- risk 0.36cvss 5.6epss 0.00
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated…
- risk 0.36cvss 5.5epss 0.01
Windows Power Management Service Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before build 32047.
- risk 0.36cvss 5.5epss 0.01
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse…
- risk 0.36cvss 5.5epss 0.00
There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail.
- risk 0.36cvss 5.6epss 0.00
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.36cvss 5.6epss 0.00
There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can…
- risk 0.36cvss 5.5epss 0.00
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.
- risk 0.36cvss 5.5epss 0.00
A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.
- risk 0.36cvss 5.5epss 0.00
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.
- risk 0.36cvss 5.5epss 0.01
A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken access control. The attack requires authentication. Upgrading to version 1.0.4.851 is able to address this issue. It is recommended to…
- risk 0.36cvss 5.5epss 0.00
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication.
- risk 0.36cvss 5.5epss 0.00
Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3…
- risk 0.36cvss 5.5epss 0.00
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
- risk 0.36cvss 5.5epss 0.01
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.