VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 160 of 255
  • CVE-2022-48305MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail.

  • CVE-2022-33946MedFeb 16, 2023
    risk 0.36cvss 5.6epss 0.00

    Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-43978MedJan 27, 2023
    risk 0.36cvss 5.6epss 0.00

    There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can…

  • CVE-2022-41590MedDec 20, 2022
    risk 0.36cvss 5.5epss 0.00

    Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.

  • CVE-2022-2752MedDec 9, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

  • CVE-2022-34331MedNov 11, 2022
    risk 0.36cvss 5.5epss 0.01

    After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.

  • CVE-2021-4142MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

  • CVE-2020-36528MedJun 7, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken access control. The attack requires authentication. Upgrading to version 1.0.4.851 is able to address this issue. It is recommended to…

  • CVE-2022-26724MedMay 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication.

  • CVE-2021-33087MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2010-2496MedOct 18, 2021
    risk 0.36cvss 5.5epss 0.00

    stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3…

  • CVE-2021-30770MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

  • CVE-2021-30769MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

  • CVE-2021-30867MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access photos.

  • CVE-2020-10048MedFeb 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected…

  • CVE-2021-1725MedJan 12, 2021
    risk 0.36cvss 5.5epss 0.01

    Bot Framework SDK Information Disclosure Vulnerability

  • CVE-2020-23139MedNov 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.

  • CVE-2020-1838MedJul 6, 2020
    risk 0.36cvss 5.5epss 0.00

    HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficiently validate certain credential of user's face, an attacker could craft the credential of the user, successful exploit could allow…

  • CVE-2020-9070MedApr 20, 2020
    risk 0.36cvss 5.5epss 0.01

    Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulnerability. The software insufficiently validate the user's identity when a user wants to do certain operation. An attacker can trick user into installing a…

  • CVE-2020-1801MedApr 10, 2020
    risk 0.36cvss 5.5epss 0.01

    There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the caller's identity in certain share scenario, successful exploit could cause information disclosure. Affected product versions…