VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 149 of 241
  • CVE-2023-48121MedNov 28, 2023
    risk 0.35cvss 5.3epss 0.01

    An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows…

  • CVE-2023-42554MedNov 7, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.

  • CVE-2023-26150MedOct 3, 2023
    risk 0.35cvss 6.5epss 0.00

    Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

  • CVE-2023-42818MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.01

    JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a disclosed public key to attempt brute-force…

  • CVE-2023-41904MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.

  • CVE-2023-40282MedAug 23, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be changed.

  • CVE-2023-32081MedMay 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.0 until 4.4.2, a Vert.x STOMP server processes client STOMP frames without checking that the client send an initial CONNECT frame…

  • CVE-2022-44610MedMay 10, 2023
    risk 0.35cvss 5.4epss 0.01

    Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-27919MedMay 10, 2023
    risk 0.35cvss 5.3epss 0.01

    Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.

  • CVE-2023-1784MedMar 31, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2022-46774MedMar 15, 2023
    risk 0.35cvss 5.4epss 0.00

    IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.

  • CVE-2022-45724MedFeb 13, 2023
    risk 0.35cvss 5.4epss 0.01

    Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated…

  • CVE-2023-22334MedJan 20, 2023
    risk 0.35cvss 5.3epss 0.01

    Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack.

  • CVE-2023-22278MedJan 17, 2023
    risk 0.35cvss 5.3epss 0.01

    m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass authentication and send users' unintended email when email is being sent under the certain conditions. The attacks exploiting this…

  • CVE-2023-0105MedJan 13, 2023
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.

  • CVE-2022-4799MedDec 28, 2022
    risk 0.35cvss 6.5epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-23540MedDec 22, 2022
    risk 0.35cvss 6.4epss 0.01

    In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected if you do not specify algorithms in the…

  • CVE-2022-46400MedDec 19, 2022
    risk 0.35cvss 5.4epss 0.01

    The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.

  • CVE-2022-32928MedNov 1, 2022
    risk 0.35cvss 5.3epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.

  • CVE-2022-21618MedOct 18, 2022
    risk 0.35cvss 5.3epss 0.02

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 21.3.3 and 22.2.0. Easily exploitable vulnerability…