VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 145 of 241
  • CVE-2021-30867MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access photos.

  • CVE-2020-10048MedFeb 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected…

  • CVE-2021-1725MedJan 12, 2021
    risk 0.36cvss 5.5epss 0.01

    Bot Framework SDK Information Disclosure Vulnerability

  • CVE-2020-23139MedNov 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.

  • CVE-2020-1838MedJul 6, 2020
    risk 0.36cvss 5.5epss 0.00

    HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficiently validate certain credential of user's face, an attacker could craft the credential of the user, successful exploit could allow…

  • CVE-2020-9070MedApr 20, 2020
    risk 0.36cvss 5.5epss 0.01

    Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulnerability. The software insufficiently validate the user's identity when a user wants to do certain operation. An attacker can trick user into installing a…

  • CVE-2020-1801MedApr 10, 2020
    risk 0.36cvss 5.5epss 0.01

    There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the caller's identity in certain share scenario, successful exploit could cause information disclosure. Affected product versions…

  • CVE-2020-10846MedMar 24, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019-16554 (February 2020).

  • CVE-2020-1878MedMar 20, 2020
    risk 0.36cvss 5.5epss 0.00

    Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit…

  • CVE-2020-9064MedMar 12, 2020
    risk 0.36cvss 5.5epss 0.00

    Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit this vulnerability to obtain some…

  • CVE-2019-3998MedFeb 13, 2020
    risk 0.36cvss 5.5epss 0.00

    Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connects to.

  • CVE-2020-1788MedJan 21, 2020
    risk 0.36cvss 5.5epss 0.01

    Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An attacker could trick the user into…

  • CVE-2019-8704MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

  • CVE-2018-20924MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.01

    cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).

  • CVE-2018-20888MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).

  • CVE-2018-3696MedNov 14, 2018
    risk 0.36cvss 5.5epss 0.00

    Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative privileges via local access.

  • CVE-2016-2125MedOct 31, 2018
    risk 0.36cvss 6.5epss 0.09

    It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

  • CVE-2018-16670MedSep 18, 2018
    risk 0.36cvss 5.3epss 0.25

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.

  • CVE-2018-11770MedAug 13, 2018
    risk 0.36cvss 4.2epss 0.66

    From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for authenticating requests…

  • CVE-2018-1106MedApr 23, 2018
    risk 0.36cvss 5.5epss 0.00

    An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.