VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 188 of 253
  • CVE-2024-45036MedAug 26, 2024
    risk 0.21cvss 4.3epss 0.00

    Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious Tophat URL controlled by the attacker. The vulnerability allows Tophat to send this token to the…

  • CVE-2024-40778LowJul 29, 2024
    risk 0.21cvss 3.3epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Photos in the Hidden Photos Album may be viewed without authentication.

  • CVE-2023-25601MedApr 20, 2023
    risk 0.21cvss 4.3epss 0.01

    On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version 3.0.0 to 3.1.1, you…

  • CVE-2023-23493LowFeb 27, 2023
    risk 0.21cvss 3.3epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3. An encrypted volume may be unmounted and remounted by a different user without prompting for the password.

  • CVE-2022-39229MedOct 13, 2022
    risk 0.21cvss 4.3epss 0.01

    Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address…

  • CVE-2022-3173MedSep 17, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.

  • CVE-2022-29858MedJun 28, 2022
    risk 0.21cvss 4.3epss 0.01

    Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.

  • CVE-2022-30749LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.

  • CVE-2022-0985MedApr 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

  • CVE-2022-27839LowApr 11, 2022
    risk 0.21cvss 3.3epss 0.01

    Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.

  • CVE-2022-25833LowApr 11, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.

  • CVE-2018-25030LowMar 28, 2022
    risk 0.21cvss 3.3epss 0.00

    A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Affected is the Auto Lock. A race condition leads to a local authentication bypass. The exploit has been disclosed to the public and may be used.

  • CVE-2022-22656LowMar 18, 2022
    risk 0.21cvss 3.3epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching…

  • CVE-2022-23807MedJan 22, 2022
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

  • CVE-2021-25505LowNov 5, 2021
    risk 0.21cvss 3.3epss 0.01

    Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.

  • CVE-2021-25451LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.

  • CVE-2021-25377LowApr 9, 2021
    risk 0.21cvss 3.3epss 0.00

    Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.

  • CVE-2021-25368LowMar 25, 2021
    risk 0.21cvss 3.3epss 0.01

    Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.

  • CVE-2020-9077LowJul 27, 2020
    risk 0.21cvss 3.3epss 0.01

    HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to…

  • CVE-2019-20533LowMar 24, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China or India) software. The S Secure app can launch masked apps without a password. The Samsung ID is SVE-2019-13996 (December 2019).