VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 167 of 241
  • CVE-2022-36106MedSep 13, 2022
    risk 0.28cvss 5.4epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the expiration time of a password reset link for TYPO3 backend users has never been evaluated. As a result, a password reset link could be used to perform a…

  • CVE-2022-35726MedAug 23, 2022
    risk 0.28cvss 4.3epss 0.01

    Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.

  • CVE-2022-2303MedAug 5, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using…

  • CVE-2022-29237MedMay 24, 2022
    risk 0.28cvss 5.4epss 0.01

    Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.14 and 11.7, users could pass along URLs for files belonging to organizations other than the user's own, which Opencast would then import into the current…

  • CVE-2022-1349MedMay 16, 2022
    risk 0.28cvss 4.3epss 0.01

    The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any users (with privileges as…

  • CVE-2022-23600MedFeb 4, 2022
    risk 0.28cvss 5.3epss 0.01

    fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in two specific cases: 1. A malicious or compromised Service…

  • CVE-2022-21692MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat participant.

  • CVE-2022-21695MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of…

  • CVE-2021-33210MedNov 3, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information without authentication by reading the response of APIs from a kiosk view of a plant.

  • CVE-2021-41580MedSep 27, 2021
    risk 0.28cvss 5.3epss 0.01

    The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token. This is exploitable in certain use cases where an OAuth identity provider uses an HTTP 200 status code for authentication-failure error reports, and an…

  • CVE-2021-25430MedJul 8, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.

  • CVE-2021-3339MedFeb 19, 2021
    risk 0.28cvss 4.3epss 0.02

    ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

  • CVE-2021-26697MedFeb 17, 2021
    risk 0.28cvss 5.3epss 0.05

    The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as the attacker needs to be aware of certain parameters to pass to that endpoint and…

  • CVE-2020-29662MedFeb 2, 2021
    risk 0.28cvss 5.3epss 0.01

    In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.

  • CVE-2019-18252MedJun 29, 2020
    risk 0.28cvss 4.3epss 0.00

    BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials used for connecting to the BIOTRONIK Remote Communication infrastructure.

  • CVE-2019-18246MedJun 29, 2020
    risk 0.28cvss 4.3epss 0.00

    BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure.

  • CVE-2019-20879MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.

  • CVE-2020-10754MedJun 8, 2020
    risk 0.28cvss 4.3epss 0.01

    It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made…

  • CVE-2011-2054MedFeb 19, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities…

  • CVE-2020-5532MedFeb 14, 2020
    risk 0.28cvss 4.3epss 0.01

    ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.