VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 29 of 241
  • CVE-2020-11965CriApr 21, 2020
    risk 0.64cvss 9.8epss 0.02

    In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has…

  • CVE-2020-9277CriApr 20, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authentication.

  • CVE-2018-21038CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsung ID is SVE-2018-11628 (December 2018).

  • CVE-2020-11542CriApr 4, 2020
    risk 0.64cvss 9.8epss 0.01

    3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the MYKEY substring.

  • CVE-2020-10888CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.02

    This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSH port…

  • CVE-2019-20489CriMar 2, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an…

  • CVE-2018-14705CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability…

  • CVE-2019-20481CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.01

    In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.

  • CVE-2014-3879CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.03

    OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login…

  • CVE-2019-20046CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.02

    The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is…

  • CVE-2020-8953CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.01

    OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

  • CVE-2019-20062CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.02

    MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

  • CVE-2013-3091CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.04

    An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

  • CVE-2020-8591CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.

  • CVE-2020-8510CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.

  • CVE-2013-3317CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.05

    Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.

  • CVE-2013-3316CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.05

    Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".

  • CVE-2013-3071CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.02

    NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.

  • CVE-2019-15585CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

  • CVE-2020-7995CriJan 26, 2020
    risk 0.64cvss 9.8epss 0.05

    The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.