VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 178 of 255
  • CVE-2023-21487MedMay 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.

  • CVE-2023-21484MedMay 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.

  • CVE-2022-46146MedNov 29, 2022
    risk 0.33cvss 6.2epss 0.01

    Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and…

  • CVE-2018-25043MedJun 17, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is…

  • CVE-2018-14637MedNov 30, 2018
    risk 0.33cvss 6.1epss 0.01

    The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.

  • CVE-2018-1672MedOct 1, 2018
    risk 0.33cvss 5.0epss 0.01

    IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.

  • CVE-2026-56080MedJun 19, 2026
    risk 0.32cvss 4.9epss 0.01

    Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat…

  • CVE-2026-9084MedMay 20, 2026
    risk 0.32cvss —epss 0.00

    MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an…

  • CVE-2026-32879MedMar 23, 2026
    risk 0.32cvss 4.9epss 0.00

    New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification…

  • CVE-2021-20018MedMar 13, 2021
    risk 0.32cvss 4.9epss 0.01

    A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.

  • CVE-2019-14553MedNov 23, 2020
    risk 0.32cvss 4.9epss 0.01

    Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.

  • CVE-2020-16239MedAug 21, 2020
    risk 0.32cvss 4.9epss 0.01

    When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficiently proves the claim is correct.

  • CVE-2020-12035MedJun 29, 2020
    risk 0.32cvss 4.9epss 0.00

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service password that provides access to biomedical information, device settings, calibration settings, and network configuration. This could allow an attacker to…

  • CVE-2019-10273MedApr 4, 2019
    risk 0.32cvss 4.3epss 0.08

    Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

  • CVE-2018-4856MedJul 3, 2018
    risk 0.32cvss 4.9epss 0.01

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative access to the device's management interface could lock out legitimate users. Manual interaction is required to restore the access of legitimate…

  • CVE-2017-16025MedJun 4, 2018
    risk 0.32cvss 5.9epss 0.02

    Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid…

  • CVE-2016-4043MedFeb 24, 2017
    risk 0.32cvss 4.9epss 0.01

    Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.

  • CVE-2016-3094MedJun 1, 2016
    risk 0.32cvss 5.9epss 0.08

    PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

  • CVE-2012-6440MedJan 24, 2013
    risk 0.32cvss 4.8epss 0.09

    The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics…

  • CVE-2024-38639MedSep 18, 2026
    risk 0.31cvss 4.8epss 0.00

    An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system. QTS is not affected. We have already fixed the vulnerability in the following version: