VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 215 of 253
  • CVE-2023-3069CriJun 2, 2023
    risk 0.00cvss 9.8epss 0.01

    Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.

  • CVE-2022-41985HigMay 10, 2023
    risk 0.00cvss 8.6epss 0.01

    An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can send a sequence of unauthenticated packets…

  • CVE-2023-31127CriMay 8, 2023
    risk 0.00cvss 9.0epss 0.01

    libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPDM session establishment in libspdm prior to version 2.3.1. If a device supports both DHE session and PSK session with mutual authentication, the attacker may…

  • CVE-2023-31123CriMay 8, 2023
    risk 0.00cvss 9.1epss 0.01

    `effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior to commit bd80ba833b9023d39ca22e29874296c8729dd53b, any user with an account on an instance of `effectindex/tripreporter`, e.g. `subjective.report`, may be…

  • CVE-2023-30845HigApr 26, 2023
    risk 0.00cvss 8.2epss 0.01

    ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authentication bypass vulnerability. API clients can craft a malicious `X-HTTP-Method-Override` header value to bypass JWT…

  • CVE-2021-40507CriApr 18, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. Any software that relies on…

  • CVE-2021-40506CriApr 18, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated for the msb and mac instructions, which results in an incorrect value in the overflow flag. Any software that relies on this…

  • CVE-2023-28647MedMar 30, 2023
    risk 0.00cvss 4.4epss 0.00

    Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.0 when an attacker has physical access to an unlocked device, they may enable the integration into the iOS Files app and bypass the Nextcloud pin/password…

  • CVE-2023-28646MedMar 30, 2023
    risk 0.00cvss 4.4epss 0.00

    Nextcloud android is an android app for interfacing with the nextcloud home server ecosystem. In versions from 3.7.0 and before 3.24.1 an attacker that has access to the unlocked physical device can bypass the Nextcloud Android Pin/passcode protection via a thirdparty app. This…

  • CVE-2022-48364MedMar 6, 2023
    risk 0.00cvss 4.3epss 0.01

    The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server's representative account, resulting in moderator identity disclosure when a moderator approves the appeal of a user whose status update was…

  • CVE-2023-1065MedFeb 28, 2023
    risk 0.00cvss 6.5epss 0.01

    This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expose the user of the integration to any direct security risk and no user data can be…

  • CVE-2022-23505MedDec 13, 2022
    risk 0.00cvss 5.3epss 0.01

    Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the…

  • CVE-2022-39355CriOct 26, 2022
    risk 0.00cvss 9.1epss 0.01

    Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabled, an improper authentication vulnerability could be used to take control of a victim's forum account. This vulnerability is patched in commit number…

  • CVE-2022-39360MedOct 26, 2022
    risk 0.00cvss 6.5epss 0.01

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is…

  • CVE-2021-36369HigOct 12, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security…

  • CVE-2022-39289CriOct 7, 2022
    risk 0.00cvss 9.1epss 0.01

    ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo…

  • CVE-2022-39264HigSep 28, 2022
    risk 0.00cvss 8.6epss 0.01

    nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a…

  • CVE-2022-39257HigSep 28, 2022
    risk 0.00cvss 7.5epss 0.01

    Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some…

  • CVE-2022-39255HigSep 28, 2022
    risk 0.00cvss 8.6epss 0.01

    Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey…

  • CVE-2022-39245HigSep 26, 2022
    risk 0.00cvss 8.4epss 0.00

    Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system with root permissions. Versions 0.9.5 and later contain a…