VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 27 of 253
  • CVE-2022-0547CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.04

    OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

  • CVE-2021-45786CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

  • CVE-2021-46384CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated…

  • CVE-2022-0730CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.04

    Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

  • CVE-2022-24047CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.02

    This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from…

  • CVE-2022-24259CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.

  • CVE-2021-43394CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.

  • CVE-2020-4879CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.

  • CVE-2021-44736CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.02

    The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.

  • CVE-2021-34993CriJan 13, 2022
    risk 0.64cvss 9.8epss 0.05

    This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService service. The issue results from the…

  • CVE-2021-33046CriJan 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.

  • CVE-2021-45389CriJan 4, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.

  • CVE-2021-21952CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to increased privileges.

  • CVE-2021-44525CriDec 20, 2021
    risk 0.64cvss 9.8epss 0.03

    Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.

  • CVE-2021-44676CriDec 20, 2021
    risk 0.64cvss 9.8epss 0.04

    Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.

  • CVE-2021-44675CriDec 20, 2021
    risk 0.64cvss 9.8epss 0.06

    Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.

  • CVE-2021-4073CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.07

    The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the…

  • CVE-2021-44524CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications…

  • CVE-2021-44514CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.05

    OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.

  • CVE-2021-41716CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function