VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 165 of 255
  • CVE-2023-42576MedDec 5, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.

  • CVE-2023-6354MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.

  • CVE-2023-6353MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.

  • CVE-2023-6344MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly…

  • CVE-2023-6343MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server,…

  • CVE-2023-6342MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" feature was removed on or…

  • CVE-2023-48121MedNov 28, 2023
    risk 0.35cvss 5.3epss 0.01

    An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows…

  • CVE-2023-42554MedNov 7, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.

  • CVE-2023-26150MedOct 3, 2023
    risk 0.35cvss 6.5epss 0.01

    Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

  • CVE-2023-42818MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.01

    JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a disclosed public key to attempt brute-force…

  • CVE-2023-41904MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.

  • CVE-2023-40282MedAug 23, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be changed.

  • CVE-2023-32081MedMay 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.0 until 4.4.2, a Vert.x STOMP server processes client STOMP frames without checking that the client send an initial CONNECT frame…

  • CVE-2022-44610MedMay 10, 2023
    risk 0.35cvss 5.4epss 0.01

    Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-27919MedMay 10, 2023
    risk 0.35cvss 5.3epss 0.01

    Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.

  • CVE-2023-1784MedMar 31, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2022-46774MedMar 15, 2023
    risk 0.35cvss 5.4epss 0.00

    IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.

  • CVE-2022-45724MedFeb 13, 2023
    risk 0.35cvss 5.4epss 0.01

    Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated…

  • CVE-2023-22334MedJan 20, 2023
    risk 0.35cvss 5.3epss 0.01

    Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack.

  • CVE-2023-22278MedJan 17, 2023
    risk 0.35cvss 5.3epss 0.01

    m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass authentication and send users' unintended email when email is being sent under the certain conditions. The attacks exploiting this…