VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 145 of 255
  • CVE-2018-13060MedMar 16, 2020
    risk 0.42cvss 6.5epss 0.01

    Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.

  • CVE-2019-19857MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password…

  • CVE-2019-17023MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.01

    After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects…

  • CVE-2019-5061MedDec 12, 2019
    risk 0.42cvss 6.5epss 0.01

    An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by…

  • CVE-2013-4593HigDec 11, 2019
    risk 0.42cvss 7.5epss 0.02

    RubyGem omniauth-facebook has an access token security vulnerability

  • CVE-2019-18380MedDec 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.

  • CVE-2019-18848HigNov 12, 2019
    risk 0.42cvss 7.5epss 0.01

    The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.

  • CVE-2019-1877MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download function of the API. An…

  • CVE-2019-17627MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.01

    The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid…

  • CVE-2019-13361MedSep 5, 2019
    risk 0.42cvss 6.5epss 0.01

    Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.

  • CVE-2019-15648MedAug 27, 2019
    risk 0.42cvss 6.5epss 0.01

    The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.

  • CVE-2018-14008MedAug 15, 2019
    risk 0.42cvss 6.5epss 0.01

    Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.

  • CVE-2019-1946MedAug 8, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerability is due to an…

  • CVE-2016-10832MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).

  • CVE-2016-10836MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).

  • CVE-2018-14868MedJun 28, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.

  • CVE-2019-10689MedJun 24, 2019
    risk 0.42cvss 6.5epss 0.01

    VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive…

  • CVE-2019-10911HigMay 16, 2019
    risk 0.42cvss 7.5epss 0.01

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related…

  • CVE-2018-17928MedJan 31, 2019
    risk 0.42cvss 6.5epss 0.01

    The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user authentication mechanism.

  • CVE-2018-19505MedJan 3, 2019
    risk 0.42cvss 6.5epss 0.02

    Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution…