VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 158 of 241
  • CVE-2024-2244MedMar 27, 2024
    risk 0.34cvss 5.3epss 0.00

    REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service invocation. The anomaly doesn’t exist with other credential combinations.

  • CVE-2022-44595MedMar 21, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.

  • CVE-2023-31189MedFeb 14, 2024
    risk 0.34cvss 5.2epss 0.00

    Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access.

  • CVE-2024-23806MedFeb 7, 2024
    risk 0.34cvss 5.3epss 0.00

    Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

  • CVE-2023-39303MedFeb 2, 2024
    risk 0.34cvss 5.3epss 0.00

    An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-50934MedFeb 2, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor authentication scheme. IBM X-Force ID: 275114.

  • CVE-2024-23792MedJan 29, 2024
    risk 0.34cvss 5.3epss 0.00

    When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the …

  • CVE-2023-6155MedDec 26, 2023
    risk 0.34cvss 5.3epss 0.01

    The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

  • CVE-2023-46963MedNov 4, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function.

  • CVE-2023-4939MedOct 21, 2023
    risk 0.34cvss 5.3epss 0.01

    The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authentication token for the /wp-json/salesmanago/v1/callbackApiV3 API endpoint which is simply a SHA1 hash of the site URL and client ID…

  • CVE-2023-41261MedOct 12, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not require authentication and allows an unauthenticated user to export a report and access the results.

  • CVE-2021-3784MedOct 4, 2023
    risk 0.34cvss 5.3epss 0.00

    Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created user without an assigned password during…

  • CVE-2023-40376MedOct 4, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X-Force ID: 263581.

  • CVE-2023-4498MedSep 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to authenticated users only

  • CVE-2023-27877MedJul 19, 2023
    risk 0.34cvss 5.3epss 0.01

    IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.

  • CVE-2023-2975MedJul 14, 2023
    risk 0.34cvss 5.3epss 0.01

    Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as…

  • CVE-2023-30559MedJul 13, 2023
    risk 0.34cvss 5.2epss 0.00

    The firmware update package for the wireless card is not properly signed and can be modified.

  • CVE-2023-0117MedMay 26, 2023
    risk 0.34cvss 5.3epss 0.00

    The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime.

  • CVE-2022-45860MedMay 3, 2023
    risk 0.34cvss 5.3epss 0.00

    A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying…

  • CVE-2023-28963MedApr 17, 2023
    risk 0.34cvss 5.3epss 0.00

    An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue affects Juniper Networks Junos OS: All…