VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 170 of 241
  • CVE-2022-38180MedAug 12, 2022
    risk 0.27cvss 5.3epss 0.01

    In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

  • CVE-2022-25816MedMar 10, 2022
    risk 0.27cvss 4.1epss 0.00

    Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication

  • CVE-2020-1778MedNov 23, 2020
    risk 0.27cvss 4.1epss 0.01

    When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.

  • CVE-2018-10847MedJul 30, 2018
    risk 0.27cvss 4.2epss 0.02

    prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session…

  • CVE-2026-35634MedApr 9, 2026
    risk 0.26cvss 5.1epss 0.00

    OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasRequest() unconditionally allows local-direct requests without validating bearer tokens or canvas capabilities. Attackers can send unauthenticated loopback HTTP…

  • CVE-2026-39411MedApr 8, 2026
    risk 0.26cvss 5.0epss 0.00

    LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentication layer trusts a client-controlled X-lobe-chat-auth header that is only XOR-obfuscated, not signed or otherwise authenticated.…

  • CVE-2023-21471MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

  • CVE-2024-20900MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.

  • CVE-2023-3597MedApr 25, 2024
    risk 0.26cvss 5.0epss 0.01

    A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication factor along with an existing one and…

  • CVE-2023-30724MedSep 6, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in GallerySearchProvider of Gallery prior to version 14.5.01.2 allows attacker to access search history.

  • CVE-2023-0264MedAug 4, 2023
    risk 0.26cvss 5.0epss 0.01

    A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session…

  • CVE-2023-38691MedAug 4, 2023
    risk 0.26cvss 5.0epss 0.00

    matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user's MXID in an OpenID exchange, allowing a bad actor to impersonate users when using the provisioning…

  • CVE-2023-31152MedMay 10, 2023
    risk 0.26cvss 4.0epss 0.00

    An Authentication Bypass Using an Alternate Path or Channel vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface allows Authentication Bypass. See SEL Service Bulletin dated 2022-11-15 for more details.

  • CVE-2023-21437MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

  • CVE-2022-23541MedDec 22, 2022
    risk 0.26cvss 5.0epss 0.01

    jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval function referring to the `secretOrPublicKey` argument from the readme link will result in incorrect…

  • CVE-2022-20923MedSep 8, 2022
    risk 0.26cvss 4.0epss 0.01

    A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to bypass authentication controls and access the IPSec VPN network. This vulnerability is due to…

  • CVE-2022-28790MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

  • CVE-2022-25832MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.

  • CVE-2022-25817MedMar 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.

  • CVE-2021-25506MedNov 5, 2021
    risk 0.26cvss 4.0epss 0.00

    Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.