VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,803)

page 241 of 241
  • CVE-1999-0987Nov 18, 1999
    risk 0.00cvss epss 0.05

    Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.

  • CVE-1999-0680Aug 9, 1999
    risk 0.00cvss epss 0.06

    Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

  • CVE-1999-0366Feb 8, 1999
    risk 0.00cvss epss 0.04

    In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.