VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,803)

page 16 of 241
  • CVE-2023-37226CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.

  • CVE-2024-7923CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in…

  • CVE-2024-7012CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP…

  • CVE-2024-42462CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

  • CVE-2024-7746CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication…

  • CVE-2024-36130CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.02

    An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

  • CVE-2024-22442CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The vulnerability could be remotely exploited to bypass authentication.

  • CVE-2024-37085MedKEVJun 25, 2024
    risk 0.64cvss 6.8epss 0.26

    VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vs…

  • CVE-2024-5432CriJun 20, 2024
    risk 0.64cvss 9.8epss 0.01

    The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on the user being supplied during the checkout through the plugin. This makes it possible for unauthenticated…

  • CVE-2024-6057CriJun 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature.

  • CVE-2024-22441CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.00

    HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

  • CVE-2024-37019CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.

  • CVE-2024-3263CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks.…

  • CVE-2023-51484CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from n/a through 3.8.

  • CVE-2023-51482CriApr 25, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Eazy Plugin Manager: from n/a through 4.1.2.

  • CVE-2023-51478CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

  • CVE-2023-51477CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyBoss Theme: from n/a through 2.4.60.

  • CVE-2023-51472CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.

  • CVE-2024-3701CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

  • CVE-2024-28012CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…