VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 182 of 255
  • CVE-2020-1794MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions…

  • CVE-2020-1793MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions…

  • CVE-2012-6340MedFeb 6, 2020
    risk 0.30cvss 4.6epss 0.01

    An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.

  • CVE-2013-5112MedJan 31, 2020
    risk 0.30cvss 4.6epss 0.01

    Evernote before 5.5.1 has insecure PIN storage

  • CVE-2019-3997MedJan 16, 2020
    risk 0.30cvss 4.6epss 0.00

    Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system.

  • CVE-2020-1786MedJan 9, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a…

  • CVE-2019-0622MedJan 8, 2019
    risk 0.30cvss 4.6epss 0.02

    An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.

  • CVE-2018-7989MedOct 17, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Mate 10 pro smartphones with the versions before BLA-AL00B 8.1.0.326(C00) have an improper authentication vulnerability. App Lock is a function to prevent unauthorized use of apps on smartphones, an attacker could directly change the lock password after a series of…

  • CVE-2017-2721MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B1…

  • CVE-2026-81703MedAug 27, 2026
    risk 0.29cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen…

  • CVE-2026-78885MedAug 25, 2026
    risk 0.29cvss 5.6epss 0.01

    A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the…

  • CVE-2026-47718MedAug 12, 2026
    risk 0.29cvss —epss 0.00

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.

  • CVE-2026-20752MedAug 11, 2026
    risk 0.29cvss 4.4epss 0.00

    Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur…

  • CVE-2026-56850MedJul 30, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and…

  • CVE-2026-48991MedJun 17, 2026
    risk 0.29cvss 5.5epss 0.00

    XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local attack conditions. Affected versions relied on a fixed localhost redirect URI without PKCE or…

  • CVE-2026-7113MedApr 27, 2026
    risk 0.29cvss 5.6epss 0.01

    A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication.…

  • CVE-2026-3194MedFeb 25, 2026
    risk 0.29cvss 4.5epss 0.00

    A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can only be executed locally. The attack's…

  • CVE-2024-35184MedMay 15, 2024
    risk 0.29cvss 5.5epss 0.00

    Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains…

  • CVE-2023-21297MedOct 30, 2023
    risk 0.29cvss 4.4epss 0.00

    In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21460MedMar 16, 2023
    risk 0.29cvss 4.4epss 0.00

    Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.