VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 22 of 241
  • CVE-2022-36755CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

  • CVE-2022-34919CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.02

    The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

  • CVE-2022-34149CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.

  • CVE-2022-22730CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-2336CriAug 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon…

  • CVE-2022-30270CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is…

  • CVE-2022-36412CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.05

    In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)

  • CVE-2022-26136CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.05

    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in…

  • CVE-2022-2141CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.

  • CVE-2021-40874CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with…

  • CVE-2022-2302CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password.

  • CVE-2022-2197CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.01

    By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and perform administrative operations.

  • CVE-2021-41506CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.02

    Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327,…

  • CVE-2022-33139CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA…

  • CVE-2022-33750CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.

  • CVE-2022-20798CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and…

  • CVE-2022-28106CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POST request.

  • CVE-2019-12254CriMay 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented…

  • CVE-2021-32984CriApr 4, 2022
    risk 0.64cvss 9.8epss 0.01

    All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, an attacker can connect to the PLC…

  • CVE-2021-32980CriApr 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to the PLC while an existing connection is already active.