VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 171 of 241
  • CVE-2021-25484MedOct 6, 2021
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.

  • CVE-2021-25343MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.00

    Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.

  • CVE-2021-25342MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.00

    Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.

  • CVE-2021-25341MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.00

    Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.

  • CVE-2017-1783MedJan 29, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857.

  • CVE-2017-7937MedMay 19, 2017
    risk 0.26cvss 4.0epss 0.01

    An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to gain unauthorized access to the user firewall when RADIUS servers are unreachable.

  • CVE-2023-29062LowNov 28, 2023
    risk 0.25cvss 3.8epss 0.00

    The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will…

  • CVE-2021-22497LowApr 12, 2021
    risk 0.25cvss 3.8epss 0.01

    Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.

  • CVE-2018-7947LowJul 31, 2018
    risk 0.25cvss 3.9epss 0.00

    Huawei mobile phones with versions earlier before Emily-AL00A 8.1.0.153(C00) have an authentication bypass vulnerability. An attacker could trick the user to connect to a malicious device. In the debug mode, the malicious software in the device may exploit the vulnerability to…

  • CVE-2026-75774LowAug 18, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely.…

  • CVE-2026-19749LowAug 13, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It…

  • CVE-2026-60357LowJul 21, 2026
    risk 0.24cvss 3.7epss 0.00

    Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-50623MedJun 12, 2026
    risk 0.24cvss 4.8epss 0.00

    An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker.…

  • CVE-2026-9373LowMay 24, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulation leads to improper authentication. The attack can be executed remotely. A high complexity level is…

  • CVE-2026-40243MedMay 6, 2026
    risk 0.24cvss 4.8epss 0.00

    Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and…

  • CVE-2026-42041MedApr 24, 2026
    risk 0.24cvss 4.8epss 0.01

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.),…

  • CVE-2026-4831LowMar 26, 2026
    risk 0.24cvss 3.7epss 0.00

    A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Performing a manipulation results in improper authentication.…

  • CVE-2026-4587LowMar 23, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument curlOptions results in improper certificate validation. The attack can be launched…

  • CVE-2025-64434MedNov 7, 2025
    risk 0.24cvss 4.7epss 0.00

    KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who compromises a virt-handler instance, could exploit these shared credentials to impersonate virt-api…

  • CVE-2025-64432MedNov 7, 2025
    risk 0.24cvss 4.7epss 0.00

    KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. It was discovered that the virt-api…