CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,804)
page 29 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11965 | Cri | 0.64 | 9.8 | 0.02 | Apr 21, 2020 | In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has… | ||
| CVE-2020-9277 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2020 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authentication. | ||
| CVE-2018-21038 | Cri | 0.64 | 9.8 | 0.01 | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsung ID is SVE-2018-11628 (December 2018). | ||
| CVE-2020-11542 | Cri | 0.64 | 9.8 | 0.01 | Apr 4, 2020 | 3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the MYKEY substring. | ||
| CVE-2020-10888 | Cri | 0.64 | 9.8 | 0.02 | Mar 25, 2020 | This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSH port… | ||
| CVE-2019-20489 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an… | ||
| CVE-2018-14705 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2020 | In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability… | ||
| CVE-2019-20481 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2020 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480. | ||
| CVE-2014-3879 | Cri | 0.64 | 9.8 | 0.03 | Feb 18, 2020 | OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login… | ||
| CVE-2019-20046 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2020 | The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is… | ||
| CVE-2020-8953 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2020 | OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication). | ||
| CVE-2019-20062 | Cri | 0.64 | 9.8 | 0.02 | Feb 10, 2020 | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used). | ||
| CVE-2013-3091 | Cri | 0.64 | 9.8 | 0.04 | Feb 7, 2020 | An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging." | ||
| CVE-2020-8591 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. | ||
| CVE-2020-8510 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password. | ||
| CVE-2013-3317 | Cri | 0.64 | 9.8 | 0.05 | Jan 29, 2020 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. | ||
| CVE-2013-3316 | Cri | 0.64 | 9.8 | 0.05 | Jan 29, 2020 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". | ||
| CVE-2013-3071 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2020 | NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass. | ||
| CVE-2019-15585 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2020 | Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account. | ||
| CVE-2020-7995 | Cri | 0.64 | 9.8 | 0.05 | Jan 26, 2020 | The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts. |
- risk 0.64cvss 9.8epss 0.02
In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authentication.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsung ID is SVE-2018-11628 (December 2018).
- risk 0.64cvss 9.8epss 0.01
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the MYKEY substring.
- risk 0.64cvss 9.8epss 0.02
This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSH port…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an…
- risk 0.64cvss 9.8epss 0.02
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability…
- risk 0.64cvss 9.8epss 0.01
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.
- risk 0.64cvss 9.8epss 0.03
OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login…
- risk 0.64cvss 9.8epss 0.02
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is…
- risk 0.64cvss 9.8epss 0.01
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
- risk 0.64cvss 9.8epss 0.02
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
- risk 0.64cvss 9.8epss 0.04
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
- risk 0.64cvss 9.8epss 0.01
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
- risk 0.64cvss 9.8epss 0.05
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
- risk 0.64cvss 9.8epss 0.05
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
- risk 0.64cvss 9.8epss 0.02
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
- risk 0.64cvss 9.8epss 0.02
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.
- risk 0.64cvss 9.8epss 0.05
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.