VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 26 of 241
  • CVE-2021-29012CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.03

    DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static…

  • CVE-2021-24148CriMar 18, 2021
    risk 0.64cvss 9.8epss 0.03

    A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

  • CVE-2021-22860CriMar 17, 2021
    risk 0.64cvss 9.8epss 0.03

    EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and…

  • CVE-2021-25315CriMar 3, 2021
    risk 0.64cvss 9.8epss 0.02

    CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3…

  • CVE-2021-21502CriFeb 9, 2021
    risk 0.64cvss 9.8epss 0.01

    Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired account may potentially exploit this vulnerability, giving them access to the same…

  • CVE-2020-10539CriFeb 5, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user password's MD5 hash stored in the database. It is also compared to a second MD5 hash, which is the same…

  • CVE-2020-15835CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the private key can remotely…

  • CVE-2020-13859CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi-bin/luci/quick/wizard…

  • CVE-2020-27488CriJan 13, 2021
    risk 0.64cvss 9.8epss 0.02

    Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofing these devices) can continue to use an unauthenticated…

  • CVE-2020-5633CriJan 13, 2021
    risk 0.64cvss 9.8epss 0.03

    Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied allows remote attackers to…

  • CVE-2012-10001CriJan 6, 2021
    risk 0.64cvss 9.8epss 0.03

    The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.

  • CVE-2020-35219CriJan 4, 2021
    risk 0.64cvss 9.8epss 0.02

    The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiViewTools_Password= and…

  • CVE-2020-25848CriDec 31, 2020
    risk 0.64cvss 9.8epss 0.02

    HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

  • CVE-2020-26030CriDec 28, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.

  • CVE-2020-24675CriDec 22, 2020
    risk 0.64cvss 9.8epss 0.01

    In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process.

  • CVE-2020-27780CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.02

    A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

  • CVE-2020-8465CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.

  • CVE-2020-4747CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.02

    IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.

  • CVE-2020-29563CriDec 12, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.

  • CVE-2020-7199CriDec 2, 2020
    risk 0.64cvss 9.8epss 0.09

    A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands,…