VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 162 of 241
  • CVE-2024-9683MedOct 17, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement.  While the risk is relatively low due to the…

  • CVE-2024-47174MedSep 26, 2024
    risk 0.31cvss 5.9epss 0.00

    Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did not verify TLS certificates on HTTPS connections. This could lead to connection details such as full URLs or credentials leaking…

  • CVE-2024-37893MedJun 17, 2024
    risk 0.31cvss 5.9epss 0.01

    Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious users to bypass the MFA-check. This allows malicious users to use password spraying to gain access to Firefly III data using…

  • CVE-2024-22247MedApr 2, 2024
    risk 0.31cvss 4.8epss 0.00

    VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the…

  • CVE-2023-4641MedDec 27, 2023
    risk 0.31cvss 4.7epss 0.00

    A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve…

  • CVE-2023-3591MedJul 17, 2023
    risk 0.31cvss 4.8epss 0.00

    Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.

  • CVE-2022-43528MedJan 5, 2023
    risk 0.31cvss 4.8epss 0.00

    Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a username and password and successfully bypass MFA requirements…

  • CVE-2022-4861MedDec 30, 2022
    risk 0.31cvss 4.8epss 0.01

    Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.

  • CVE-2022-23501MedDec 14, 2022
    risk 0.31cvss 5.9epss 0.00

    TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different storage folders (partitions),…

  • CVE-2016-2124MedFeb 18, 2022
    risk 0.31cvss 5.9epss 0.02

    A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.

  • CVE-2019-15796MedMar 26, 2020
    risk 0.31cvss 4.7epss 0.01

    Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows downloads from unsigned repositories which shouldn't be allowed and…

  • CVE-2019-13531MedNov 8, 2019
    risk 0.31cvss 4.8epss 0.00

    In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism used for authentication between…

  • CVE-2019-5426MedApr 10, 2019
    risk 0.31cvss 4.8epss 0.01

    In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic…

  • CVE-2019-1758MedMar 28, 2019
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication. The vulnerability is due to how the 802.1x packets are handled in the process path. An…

  • CVE-2018-18014MedOct 24, 2018
    risk 0.31cvss 4.8epss 0.00

    * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is…

  • CVE-2018-0247MedMay 2, 2018
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerability is due to…

  • CVE-2017-14018MedDec 5, 2017
    risk 0.31cvss 4.8epss 0.00

    An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products…

  • CVE-2026-33473MedMar 24, 2026
    risk 0.30cvss 5.7epss 0.00

    Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any user that has enabled 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.2.1 patches the issue.

  • CVE-2025-59704MedDec 2, 2025
    risk 0.30cvss 4.6epss 0.00

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the the BIOS menu because is has no password.

  • CVE-2023-21467MedSep 3, 2025
    risk 0.30cvss 4.6epss 0.00

    Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.