VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 166 of 241
  • CVE-2023-45038MedSep 6, 2024
    risk 0.28cvss 4.3epss 0.01

    An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0…

  • CVE-2024-42164MedAug 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.

  • CVE-2024-40648MedJul 18, 2024
    risk 0.28cvss 5.4epss 0.00

    matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check…

  • CVE-2024-27867MedJun 26, 2024
    risk 0.28cvss 4.3epss 0.01

    An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices,…

  • CVE-2024-37233MedJun 24, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Play.Ht: from n/a through 3.6.4.

  • CVE-2024-37897MedJun 20, 2024
    risk 0.28cvss 5.4epss 0.00

    SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and WebClient support password reset. This feature is disabled in the default configuration. In SFTPGo versions prior to v2.6.1, if the…

  • CVE-2024-38351MedJun 18, 2024
    risk 0.28cvss 5.4epss 0.00

    Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In order to be exploited users must have both OAuth2 and Password auth methods enabled. A possible attack scenario could be: 1. a…

  • CVE-2024-37152MedJun 6, 2024
    risk 0.28cvss 5.3epss 0.02

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This…

  • CVE-2024-20856MedMay 7, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.

  • CVE-2022-34887MedOct 27, 2023
    risk 0.28cvss 4.3epss 0.00

    Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.

  • CVE-2023-5329MedOct 2, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api/ of the component Web API. The manipulation leads to improper authentication. The exploit has been disclosed to the public and…

  • CVE-2023-4242MedAug 9, 2023
    risk 0.28cvss 4.3epss 0.01

    The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to obtain sensitive…

  • CVE-2023-3622MedJul 26, 2023
    risk 0.28cvss 4.3epss 0.01

    Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource

  • CVE-2023-32682MedJun 6, 2023
    risk 0.28cvss 5.4epss 0.01

    Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon configurations. This only applies if any of the following are true: 1. JSON Web Tokens are enabled…

  • CVE-2022-46773MedMar 15, 2023
    risk 0.28cvss 4.3epss 0.01

    IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.

  • CVE-2023-21425MedFeb 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.

  • CVE-2023-21419MedFeb 9, 2023
    risk 0.28cvss 4.3epss 0.00

    An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.

  • CVE-2022-29838MedDec 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Digital My Cloud My Cloud versions prior…

  • CVE-2022-43504MedDec 5, 2022
    risk 0.28cvss 5.3epss 0.01

    Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all…

  • CVE-2022-26508MedNov 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access.