VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,803)

page 17 of 241
  • CVE-2024-28009CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…

  • CVE-2024-28007CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…

  • CVE-2023-31634CriMar 27, 2024
    risk 0.64cvss 9.8epss 0.01

    In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for remote operations. At that time, the…

  • CVE-2024-1148CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.

  • CVE-2024-1147CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.

  • CVE-2024-0799CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.04

    An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

  • CVE-2023-49340CriMar 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.

  • CVE-2024-20738CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access.…

  • CVE-2024-24830CriFeb 8, 2024
    risk 0.64cvss 9.9epss 0.01

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to…

  • CVE-2024-22394CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.

  • CVE-2024-24592CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.

  • CVE-2024-1039CriFeb 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.

  • CVE-2023-49262CriJan 12, 2024
    risk 0.64cvss 9.8epss 0.01

    The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.

  • CVE-2023-51717CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

  • CVE-2023-31224CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    There is broken access control during authentication in Jamf Pro Server before 10.46.1.

  • CVE-2023-43742CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the…

  • CVE-2023-36655CriDec 6, 2023
    risk 0.64cvss 9.8epss 0.01

    The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.

  • CVE-2023-41264CriNov 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and…

  • CVE-2023-41999CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.

  • CVE-2023-2437CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.07

    The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers…