VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 190 of 253
  • CVE-2025-25201MedFeb 12, 2025
    risk 0.19cvss 4.0epss 0.00

    Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for authentication of the admin key. This could lead to compromise of the integrity of the data…

  • CVE-2026-71326LowAug 6, 2026
    risk 0.18cvss 3.8epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation…

  • CVE-2026-14214LowAug 1, 2026
    risk 0.18cvss 2.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the…

  • CVE-2024-38822LowJun 13, 2025
    risk 0.18cvss 2.7epss 0.00

    Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.

  • CVE-2024-6219LowDec 6, 2024
    risk 0.18cvss 3.8epss 0.00

    Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.

  • CVE-2023-35901LowJul 17, 2023
    risk 0.18cvss 2.7epss 0.00

    IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380.

  • CVE-2022-22283LowJan 10, 2022
    risk 0.18cvss 2.8epss 0.00

    Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.

  • CVE-2021-21544LowApr 30, 2021
    risk 0.18cvss 2.7epss 0.01

    Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to…

  • CVE-2019-15620LowFeb 4, 2020
    risk 0.18cvss 2.7epss 0.01

    Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.

  • CVE-2026-85716LowSep 17, 2026
    risk 0.17cvss 3.7epss 0.00

    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Digest rspauth…

  • CVE-2026-0633LowJan 24, 2026
    risk 0.17cvss 3.7epss 0.00

    The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.0. This is due to the use of a forgeable cookie value derived only from the entry ID and…

  • CVE-2024-5798LowJun 12, 2024
    risk 0.17cvss 2.6epss 0.00

    Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match, allowing an invalid login to succeed…

  • CVE-2022-39231LowSep 23, 2022
    risk 0.17cvss 3.7epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.16, or from 5.0.0 to 5.2.6, validation of the authentication adapter app ID for _Facebook_ and _Spotify_ may be circumvented. Configurations which…

  • CVE-2016-8609LowAug 1, 2018
    risk 0.17cvss 3.7epss 0.02

    It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.

  • CVE-2024-27835LowMay 14, 2024
    risk 0.16cvss 2.4epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to access notes from the lock screen.

  • CVE-2024-23255LowMar 8, 2024
    risk 0.16cvss 2.4epss 0.01

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.

  • CVE-2023-41900LowSep 15, 2023
    risk 0.16cvss 3.5epss 0.01

    Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to revoke an already…

  • CVE-2022-33720LowAug 5, 2022
    risk 0.16cvss 2.4epss 0.00

    Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.

  • CVE-2021-1863LowSep 8, 2021
    risk 0.16cvss 2.4epss 0.00

    An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone…

  • CVE-2020-1833LowMay 29, 2020
    risk 0.16cvss 2.4epss 0.00

    Honor 9X smartphones with versions earlier than 9.1.1.172(C00E170R8P1) have an improper authentication vulnerability. A logic error occurs when handling clock function, an attacker should do a series of crafted operations quickly before the phone is unlocked, successful exploit…