VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,803)

page 21 of 241
  • CVE-2022-31685CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

  • CVE-2022-27510CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauthorized access to Gateway user capabilities

  • CVE-2022-2572CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.

  • CVE-2022-41648CriOct 28, 2022
    risk 0.64cvss 9.8epss 0.01

    The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on…

  • CVE-2022-37914CriOct 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges…

  • CVE-2022-37913CriOct 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges…

  • CVE-2022-43400CriOct 21, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of Administrators group. This could allow…

  • CVE-2022-31122CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain details of SAML IdP metadata, and configures their own SAML on the same backend, the attacker can delete…

  • CVE-2022-38982CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.

  • CVE-2022-40664CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.03

    Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

  • CVE-2022-40494CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.02

    NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.

  • CVE-2022-28321CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with…

  • CVE-2022-40144CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.

  • CVE-2022-39009CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.

  • CVE-2021-42949CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.06

    The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

  • CVE-2022-37164CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the…

  • CVE-2022-37163CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to…

  • CVE-2022-34372CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter…

  • CVE-2022-38557CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

  • CVE-2022-38556CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.