VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 175 of 241
  • CVE-2021-25505LowNov 5, 2021
    risk 0.21cvss 3.3epss 0.01

    Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.

  • CVE-2021-25451LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.

  • CVE-2021-25377LowApr 9, 2021
    risk 0.21cvss 3.3epss 0.00

    Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.

  • CVE-2021-25368LowMar 25, 2021
    risk 0.21cvss 3.3epss 0.01

    Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.

  • CVE-2020-9077LowJul 27, 2020
    risk 0.21cvss 3.3epss 0.01

    HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to…

  • CVE-2019-20533LowMar 24, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China or India) software. The S Secure app can launch masked apps without a password. The Samsung ID is SVE-2019-13996 (December 2019).

  • CVE-2017-2604MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).

  • CVE-2026-9398LowMay 24, 2026
    risk 0.20cvss 3.1epss 0.00

    A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown part of the component BLE/WiFi. Such manipulation leads to authentication bypass by capture-replay. The attack must be carried out from within the local network.…

  • CVE-2026-33248MedMar 25, 2026
    risk 0.20cvss 4.2epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns…

  • CVE-2026-1743LowFeb 2, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass by capture-replay. The attack must be…

  • CVE-2025-59280LowOct 14, 2025
    risk 0.20cvss 3.1epss 0.00

    Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.

  • CVE-2025-7703LowJul 16, 2025
    risk 0.20cvss 3.1epss 0.00

    Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.

  • CVE-2025-6524LowJun 23, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability classified as problematic has been found in 70mai 1S up to 20250611. This affects an unknown part of the component Video Services. The manipulation leads to improper authentication. Access to the local network is required for this attack to succeed. The…

  • CVE-2024-39767MedJul 15, 2024
    risk 0.20cvss 4.2epss 0.00

    Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in…

  • CVE-2024-23637MedJan 31, 2024
    risk 0.20cvss 4.2epss 0.01

    OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password. An attacker who…

  • CVE-2023-47127MedNov 14, 2023
    risk 0.20cvss 4.2epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected versions a session cookie generated for the first site can…

  • CVE-2023-34246MedJun 12, 2023
    risk 0.20cvss 4.2epss 0.01

    Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation,…

  • CVE-2023-0858LowMay 11, 2023
    risk 0.20cvss 3.1epss 0.01

    Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware…

  • CVE-2022-32971LowFeb 16, 2023
    risk 0.20cvss 3.1epss 0.00

    Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2022-0862LowMar 23, 2022
    risk 0.20cvss 3.1epss 0.01

    A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the existing user's password. This…