CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,090)
page 145 of 255| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-13060 | Med | 0.42 | 6.5 | 0.01 | Mar 16, 2020 | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue. | ||
| CVE-2019-19857 | Med | 0.42 | 6.5 | 0.01 | Jan 15, 2020 | An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password… | ||
| CVE-2019-17023 | Med | 0.42 | 6.5 | 0.01 | Jan 8, 2020 | After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects… | ||
| CVE-2019-5061 | Med | 0.42 | 6.5 | 0.01 | Dec 12, 2019 | An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by… | ||
| CVE-2013-4593 | Hig | 0.42 | 7.5 | 0.02 | Dec 11, 2019 | RubyGem omniauth-facebook has an access token security vulnerability | ||
| CVE-2019-18380 | Med | 0.42 | 6.5 | 0.01 | Dec 9, 2019 | Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication. | ||
| CVE-2019-18848 | Hig | 0.42 | 7.5 | 0.01 | Nov 12, 2019 | The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. | ||
| CVE-2019-1877 | Med | 0.42 | 6.5 | 0.01 | Nov 5, 2019 | A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download function of the API. An… | ||
| CVE-2019-17627 | Med | 0.42 | 6.5 | 0.01 | Oct 16, 2019 | The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid… | ||
| CVE-2019-13361 | Med | 0.42 | 6.5 | 0.01 | Sep 5, 2019 | Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network. | ||
| CVE-2019-15648 | Med | 0.42 | 6.5 | 0.01 | Aug 27, 2019 | The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. | ||
| CVE-2018-14008 | Med | 0.42 | 6.5 | 0.01 | Aug 15, 2019 | Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled. | ||
| CVE-2019-1946 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2019 | A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerability is due to an… | ||
| CVE-2016-10832 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102). | ||
| CVE-2016-10836 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). | ||
| CVE-2018-14868 | Med | 0.42 | 6.5 | 0.01 | Jun 28, 2019 | Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call. | ||
| CVE-2019-10689 | Med | 0.42 | 6.5 | 0.01 | Jun 24, 2019 | VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive… | ||
| CVE-2019-10911 | Hig | 0.42 | 7.5 | 0.01 | May 16, 2019 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related… | ||
| CVE-2018-17928 | Med | 0.42 | 6.5 | 0.01 | Jan 31, 2019 | The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user authentication mechanism. | ||
| CVE-2018-19505 | Med | 0.42 | 6.5 | 0.02 | Jan 3, 2019 | Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution… |
- risk 0.42cvss 6.5epss 0.01
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password…
- risk 0.42cvss 6.5epss 0.01
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects…
- risk 0.42cvss 6.5epss 0.01
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by…
- risk 0.42cvss 7.5epss 0.02
RubyGem omniauth-facebook has an access token security vulnerability
- risk 0.42cvss 6.5epss 0.01
Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.
- risk 0.42cvss 7.5epss 0.01
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download function of the API. An…
- risk 0.42cvss 6.5epss 0.01
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid…
- risk 0.42cvss 6.5epss 0.01
Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.
- risk 0.42cvss 6.5epss 0.01
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
- risk 0.42cvss 6.5epss 0.01
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerability is due to an…
- risk 0.42cvss 6.5epss 0.01
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
- risk 0.42cvss 6.5epss 0.01
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
- risk 0.42cvss 6.5epss 0.01
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
- risk 0.42cvss 6.5epss 0.01
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive…
- risk 0.42cvss 7.5epss 0.01
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related…
- risk 0.42cvss 6.5epss 0.01
The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user authentication mechanism.
- risk 0.42cvss 6.5epss 0.02
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution…