VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 150 of 241
  • CVE-2022-27484MedAug 3, 2022
    risk 0.35cvss 5.4epss 0.00

    A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.

  • CVE-2022-35629MedJul 29, 2022
    risk 0.35cvss 5.4epss 0.00

    Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2.

  • CVE-2022-28666MedJul 21, 2022
    risk 0.35cvss 5.3epss 0.01

    Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.

  • CVE-2022-2133MedJul 17, 2022
    risk 0.35cvss 5.3epss 0.01

    The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.

  • CVE-2015-5298MedJul 7, 2022
    risk 0.35cvss 6.5epss 0.01

    The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.

  • CVE-2022-28713MedJul 4, 2022
    risk 0.35cvss 5.3epss 0.01

    Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Information without logging in to the product.

  • CVE-2022-29578MedJun 24, 2022
    risk 0.35cvss 5.3epss 0.01

    Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information such as name, address, and daily energy usage.

  • CVE-2022-20733MedJun 15, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup…

  • CVE-2022-29883MedMay 20, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the web interface. This could allow an attacker to delete log files without authentication.

  • CVE-2020-14504MedFeb 24, 2022
    risk 0.35cvss 5.3epss 0.01

    The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.

  • CVE-2021-36346MedJan 25, 2022
    risk 0.35cvss 5.3epss 0.04

    Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver.

  • CVE-2022-22289MedJan 10, 2022
    risk 0.35cvss 5.3epss 0.01

    Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.

  • CVE-2021-44937MedDec 14, 2021
    risk 0.35cvss 5.3epss 0.01

    glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailbox has been occupied.

  • CVE-2021-43068MedDec 9, 2021
    risk 0.35cvss 5.4epss 0.01

    A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.

  • CVE-2021-41309MedDec 8, 2021
    risk 0.35cvss 5.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the…

  • CVE-2021-38376MedNov 22, 2021
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.

  • CVE-2021-32951MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.01

    WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices managed via WebAccess/NMS.

  • CVE-2021-24017MedSep 30, 2021
    risk 0.35cvss 5.4epss 0.01

    An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.

  • CVE-2021-30667MedSep 8, 2021
    risk 0.35cvss 5.4epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force a client to use a less secure authentication mechanism.

  • CVE-2021-30720MedSep 8, 2021
    risk 0.35cvss 5.4epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.