CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,803)
page 17 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-28009 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2024 | Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,… | ||
| CVE-2024-28007 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2024 | Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,… | ||
| CVE-2023-31634 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2024 | In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for remote operations. At that time, the… | ||
| CVE-2024-1148 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2024 | Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files. | ||
| CVE-2024-1147 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2024 | Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files. | ||
| CVE-2024-0799 | Cri | 0.64 | 9.8 | 0.04 | Mar 13, 2024 | An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin. | ||
| CVE-2023-49340 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2024 | An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal. | ||
| CVE-2024-20738 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2024 | Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access.… | ||
| CVE-2024-24830 | Cri | 0.64 | 9.9 | 0.01 | Feb 8, 2024 | OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to… | ||
| CVE-2024-22394 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1.1-7040. | ||
| CVE-2024-24592 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2024 | Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files. | ||
| CVE-2024-1039 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2024 | Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device. | ||
| CVE-2023-49262 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2024 | The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session. | ||
| CVE-2023-51717 | Cri | 0.64 | 9.8 | 0.01 | Jan 9, 2024 | Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. | ||
| CVE-2023-31224 | Cri | 0.64 | 9.8 | 0.01 | Dec 25, 2023 | There is broken access control during authentication in Jamf Pro Server before 10.46.1. | ||
| CVE-2023-43742 | Cri | 0.64 | 9.8 | 0.01 | Dec 8, 2023 | An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the… | ||
| CVE-2023-36655 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2023 | The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination. | ||
| CVE-2023-41264 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2023 | Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and… | ||
| CVE-2023-41999 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication. | ||
| CVE-2023-2437 | Cri | 0.64 | 9.8 | 0.07 | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers… |
- risk 0.64cvss 9.8epss 0.01
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…
- risk 0.64cvss 9.8epss 0.01
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP,…
- risk 0.64cvss 9.8epss 0.01
In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for remote operations. At that time, the…
- risk 0.64cvss 9.8epss 0.01
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.
- risk 0.64cvss 9.8epss 0.01
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.
- risk 0.64cvss 9.8epss 0.04
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.
- risk 0.64cvss 9.8epss 0.01
Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access.…
- risk 0.64cvss 9.9epss 0.01
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to…
- risk 0.64cvss 9.8epss 0.01
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1.1-7040.
- risk 0.64cvss 9.8epss 0.01
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.
- risk 0.64cvss 9.8epss 0.01
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
- risk 0.64cvss 9.8epss 0.01
The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.
- risk 0.64cvss 9.8epss 0.01
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
- risk 0.64cvss 9.8epss 0.01
There is broken access control during authentication in Jamf Pro Server before 10.46.1.
- risk 0.64cvss 9.8epss 0.01
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the…
- risk 0.64cvss 9.8epss 0.01
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.
- risk 0.64cvss 9.8epss 0.01
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and…
- risk 0.64cvss 9.8epss 0.01
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.
- risk 0.64cvss 9.8epss 0.07
The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers…