VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 161 of 255
  • CVE-2020-10846MedMar 24, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019-16554 (February 2020).

  • CVE-2020-1878MedMar 20, 2020
    risk 0.36cvss 5.5epss 0.00

    Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit…

  • CVE-2020-9064MedMar 12, 2020
    risk 0.36cvss 5.5epss 0.00

    Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit this vulnerability to obtain some…

  • CVE-2019-3998MedFeb 13, 2020
    risk 0.36cvss 5.5epss 0.00

    Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connects to.

  • CVE-2020-1788MedJan 21, 2020
    risk 0.36cvss 5.5epss 0.01

    Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An attacker could trick the user into…

  • CVE-2019-8704MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

  • CVE-2018-20924MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.01

    cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).

  • CVE-2018-20888MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).

  • CVE-2018-3696MedNov 14, 2018
    risk 0.36cvss 5.5epss 0.00

    Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative privileges via local access.

  • CVE-2016-2125MedOct 31, 2018
    risk 0.36cvss 6.5epss 0.09

    It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

  • CVE-2018-16670MedSep 18, 2018
    risk 0.36cvss 5.3epss 0.25

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.

  • CVE-2018-11770MedAug 13, 2018
    risk 0.36cvss 4.2epss 0.66

    From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for authenticating requests…

  • CVE-2018-1106MedApr 23, 2018
    risk 0.36cvss 5.5epss 0.00

    An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.

  • CVE-2017-12549MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2014-8180MedJun 6, 2017
    risk 0.36cvss 5.5epss 0.00

    MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.

  • CVE-2016-5410MedApr 19, 2017
    risk 0.36cvss 5.5epss 0.00

    firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.

  • CVE-2016-3176MedJan 31, 2017
    risk 0.36cvss 5.6epss 0.01

    Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

  • CVE-2026-101050MedSep 27, 2026
    risk 0.35cvss 6.5epss 0.00

    Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_token is empty. Remote unauthenticated attackers can post forged Telegram updates to trigger workflows with the owner's configured…

  • CVE-2026-101049MedSep 27, 2026
    risk 0.35cvss 6.5epss 0.00

    Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials.

  • CVE-2026-101042MedSep 27, 2026
    risk 0.35cvss 6.4epss 0.00

    Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization…