VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 161 of 241
  • CVE-2021-20018MedMar 13, 2021
    risk 0.32cvss 4.9epss 0.01

    A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.

  • CVE-2019-14553MedNov 23, 2020
    risk 0.32cvss 4.9epss 0.01

    Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.

  • CVE-2020-16239MedAug 21, 2020
    risk 0.32cvss 4.9epss 0.01

    When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficiently proves the claim is correct.

  • CVE-2020-12035MedJun 29, 2020
    risk 0.32cvss 4.9epss 0.00

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service password that provides access to biomedical information, device settings, calibration settings, and network configuration. This could allow an attacker to…

  • CVE-2019-10273MedApr 4, 2019
    risk 0.32cvss 4.3epss 0.08

    Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

  • CVE-2018-4856MedJul 3, 2018
    risk 0.32cvss 4.9epss 0.01

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative access to the device's management interface could lock out legitimate users. Manual interaction is required to restore the access of legitimate…

  • CVE-2017-16025MedJun 4, 2018
    risk 0.32cvss 5.9epss 0.02

    Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid…

  • CVE-2016-4043MedFeb 24, 2017
    risk 0.32cvss 4.9epss 0.01

    Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.

  • CVE-2016-3094MedJun 1, 2016
    risk 0.32cvss 5.9epss 0.08

    PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

  • CVE-2012-6440MedJan 24, 2013
    risk 0.32cvss 4.8epss 0.09

    The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics…

  • CVE-2026-19971MedAug 17, 2026
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of the component Backup Endpoint. This manipulation causes missing authentication. The attack is only possible within the local network. The vendor was contacted…

  • CVE-2026-72917MedAug 10, 2026
    risk 0.31cvss 5.9epss 0.00

    AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js uses recoverAccount() to deduplicate…

  • CVE-2026-16269MedAug 8, 2026
    risk 0.31cvss 4.8epss 0.00

    The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when…

  • CVE-2026-56294MedJun 20, 2026
    risk 0.31cvss 4.8epss 0.00

    capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass…

  • CVE-2026-45691MedJun 1, 2026
    risk 0.31cvss 5.9epss 0.00

    Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful password authentication but before TOTP completion) could be reused as a Bearer…

  • CVE-2026-45690MedJun 1, 2026
    risk 0.31cvss 5.9epss 0.00

    Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's password to circumvent two-factor…

  • CVE-2026-28465MedMar 5, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating…

  • CVE-2025-15581MedFeb 18, 2026
    risk 0.31cvss epss 0.00

    Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

  • CVE-2025-29773MedMar 13, 2025
    risk 0.31cvss 5.8epss 0.00

    Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the same email address as an existing account. This creates potential issues with account identification and…

  • CVE-2025-1024MedFeb 19, 2025
    risk 0.31cvss 4.8epss 0.00

    A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page. This requires Administration privileges and affects the EID parameter. The flaw…