VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 165 of 241
  • CVE-2023-21460MedMar 16, 2023
    risk 0.29cvss 4.4epss 0.00

    Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.

  • CVE-2021-33083MedMay 12, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper authentication in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow an privileged user to potentially enable information disclosure via local access.

  • CVE-2020-8685MedAug 13, 2020
    risk 0.29cvss 4.4epss 0.00

    Improper authentication in subsystem for Intel (R) LED Manager for NUC before version 1.2.3 may allow privileged user to potentially enable denial of service via local access.

  • CVE-2017-3912MedSep 18, 2018
    risk 0.29cvss 4.4epss 0.00

    Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.

  • CVE-2026-44584MedJul 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate the existing verification state when a user changes their email address, allowing a verified account to retain…

  • CVE-2026-34917MedJun 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session…

  • CVE-2026-40995MedJun 11, 2026
    risk 0.28cvss 5.4epss 0.00

    X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected…

  • CVE-2026-24241MedFeb 24, 2026
    risk 0.28cvss 4.3epss 0.01

    NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication issue. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-22764MedJan 29, 2026
    risk 0.28cvss 4.3epss 0.00

    Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

  • CVE-2026-24003MedJan 26, 2026
    risk 0.28cvss 4.3epss 0.00

    EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification including authentication, and send requests that transition to forbidden states relative to the current one, thereby updating the current…

  • CVE-2025-14746MedDec 16, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endpoint. Such manipulation leads to improper authentication. The attack must be carried out from within the local network. The…

  • CVE-2025-65431MedDec 15, 2025
    risk 0.28cvss 5.4epss 0.00

    An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub…

  • CVE-2025-10684MedDec 12, 2025
    risk 0.28cvss 4.3epss 0.00

    The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

  • CVE-2025-62398MedOct 23, 2025
    risk 0.28cvss 5.4epss 0.00

    A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

  • CVE-2025-6528MedJun 23, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /livestream/12 of the component RTSP Live Video Stream Endpoint. The manipulation leads to improper authentication.…

  • CVE-2025-6083MedJun 13, 2025
    risk 0.28cvss 4.3epss 0.00

    In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specific owner_id.

  • CVE-2025-49012MedJun 5, 2025
    risk 0.28cvss 5.4epss 0.00

    Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.14 and 1.00-alpha are vulnerable to a privilege escalation issue when Entra ID group-based access restrictions are configured using group display names instead…

  • CVE-2025-3627MedApr 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

  • CVE-2025-27425MedMar 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.

  • CVE-2024-56445MedJan 8, 2025
    risk 0.28cvss 4.3epss 0.00

    Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.