VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 170 of 255
  • CVE-2019-1980MedNov 5, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The…

  • CVE-2016-10983MedSep 17, 2019
    risk 0.35cvss 6.5epss 0.02

    The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.

  • CVE-2019-13190MedSep 5, 2019
    risk 0.35cvss 5.3epss 0.01

    In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.

  • CVE-2019-3884MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.

  • CVE-2019-10966MedJul 10, 2019
    risk 0.35cvss 5.3epss 0.01

    In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.

  • CVE-2019-12845MedJul 3, 2019
    risk 0.35cvss 5.3epss 0.01

    The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.

  • CVE-2019-1842MedJun 5, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vulnerability is due to a logic error that may occur when…

  • CVE-2019-12395MedMay 28, 2019
    risk 0.35cvss 5.3epss 0.02

    In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting.

  • CVE-2018-0382MedApr 17, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists…

  • CVE-2019-0282MedApr 10, 2019
    risk 0.35cvss 5.3epss 0.01

    Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like release information, Java package and Java object names which…

  • CVE-2019-1759MedMar 28, 2019
    risk 0.35cvss 5.3epss 0.04

    A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability…

  • CVE-2017-2659MedMar 21, 2019
    risk 0.35cvss 5.3epss 0.02

    It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

  • CVE-2019-1666MedFeb 21, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by…

  • CVE-2018-19000MedFeb 5, 2019
    risk 0.35cvss 5.3epss 0.09

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.

  • CVE-2018-1668MedJan 29, 2019
    risk 0.35cvss 5.3epss 0.01

    IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.

  • CVE-2018-16467MedOct 30, 2018
    risk 0.35cvss 5.3epss 0.01

    A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.

  • CVE-2018-16465MedOct 30, 2018
    risk 0.35cvss 5.3epss 0.01

    Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load.

  • CVE-2018-16737MedOct 10, 2018
    risk 0.35cvss 5.3epss 0.01

    tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.

  • CVE-2018-1539MedSep 25, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.

  • CVE-2018-16668MedSep 18, 2018
    risk 0.35cvss 5.3epss 0.10

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.