VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 176 of 255
  • CVE-2023-41261MedOct 12, 2023
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not require authentication and allows an unauthenticated user to export a report and access the results.

  • CVE-2021-3784MedOct 4, 2023
    risk 0.34cvss 5.3epss 0.00

    Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created user without an assigned password during…

  • CVE-2023-40376MedOct 4, 2023
    risk 0.34cvss 5.3epss 0.01

    IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X-Force ID: 263581.

  • CVE-2023-4498MedSep 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to authenticated users only

  • CVE-2023-27877MedJul 19, 2023
    risk 0.34cvss 5.3epss 0.01

    IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.

  • CVE-2023-2975MedJul 14, 2023
    risk 0.34cvss 5.3epss 0.01

    Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as…

  • CVE-2023-30559MedJul 13, 2023
    risk 0.34cvss 5.2epss 0.00

    The firmware update package for the wireless card is not properly signed and can be modified.

  • CVE-2023-0117MedMay 26, 2023
    risk 0.34cvss 5.3epss 0.00

    The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime.

  • CVE-2022-45860MedMay 3, 2023
    risk 0.34cvss 5.3epss 0.00

    A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying…

  • CVE-2023-28963MedApr 17, 2023
    risk 0.34cvss 5.3epss 0.00

    An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue affects Juniper Networks Junos OS: All…

  • CVE-2023-28962MedApr 17, 2023
    risk 0.34cvss 5.3epss 0.01

    An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issue affects Juniper Networks Junos OS: All…

  • CVE-2023-20012MedFeb 23, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability is due to the…

  • CVE-2015-10083MedFeb 21, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use…

  • CVE-2021-4314MedJan 18, 2023
    risk 0.34cvss 5.3epss 0.00

    It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What…

  • CVE-2022-46313MedDec 20, 2022
    risk 0.34cvss 5.3epss 0.00

    The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.

  • CVE-2022-43557MedDec 5, 2022
    risk 0.34cvss 5.3epss 0.00

    The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health…

  • CVE-2022-43900MedDec 1, 2022
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827.

  • CVE-2022-37774MedNov 23, 2022
    risk 0.34cvss 5.3epss 0.01

    There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's…

  • CVE-2022-43690MedNov 14, 2022
    risk 0.34cvss 6.3epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authentication bypass could occur if using this functionality. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.

  • CVE-2022-40703MedOct 26, 2022
    risk 0.34cvss 5.2epss 0.00

    CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter…