VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 31 of 253
  • CVE-2020-7533CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.02

    CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.

  • CVE-2020-29127CriNov 30, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang…

  • CVE-2020-28333CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.03

    Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end…

  • CVE-2020-28638CriNov 13, 2020
    risk 0.64cvss 9.8epss 0.01

    ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

  • CVE-2020-26168CriNov 9, 2020
    risk 0.64cvss 9.8epss 0.02

    The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they…

  • CVE-2020-26542CriNov 9, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a…

  • CVE-2020-25592CriNov 6, 2020
    risk 0.64cvss 9.8epss 0.58

    In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

  • CVE-2020-7197CriOct 26, 2020
    risk 0.64cvss 9.8epss 0.02

    SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console…

  • CVE-2020-24629CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.03

    A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-12126CriOct 2, 2020
    risk 0.64cvss 9.8epss 0.01

    Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.

  • CVE-2020-26105CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

  • CVE-2020-26101CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).

  • CVE-2019-16028CriSep 23, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due…

  • CVE-2020-16098CriSep 15, 2020
    risk 0.64cvss 9.8epss 0.01

    It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions of 8.10 prior to v8.10.1211(MR5), versions of 8.00 prior to v8.00.1228(MR6), all versions of 7.90…

  • CVE-2020-15787CriSep 9, 2020
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a set number of characters versus the whole provided string.…

  • CVE-2020-24987CriSep 4, 2020
    risk 0.64cvss 9.8epss 0.03

    Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in /usr/lib/lua/ngx_authserver/ngx_wdas.lua file if the administrator UI Interface…

  • CVE-2020-24029CriSep 2, 2020
    risk 0.64cvss 9.8epss 0.02

    Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "corrected in all maintained versions. Password reset…

  • CVE-2020-16169CriAug 7, 2020
    risk 0.64cvss 9.8epss 0.02

    Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it automatically answer the attacker's calls, granting audio, video, and motor control…

  • CVE-2020-5608CriAug 5, 2020
    risk 0.64cvss 9.8epss 0.02

    CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass…

  • CVE-2020-5616CriAug 4, 2020
    risk 0.64cvss 9.8epss 0.03

    [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and…