CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,056)
page 33 of 253| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11542 | Cri | 0.64 | 9.8 | 0.01 | Apr 4, 2020 | 3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the MYKEY substring. | ||
| CVE-2020-10888 | Cri | 0.64 | 9.8 | 0.02 | Mar 25, 2020 | This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSH port… | ||
| CVE-2019-20489 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an… | ||
| CVE-2018-14705 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2020 | In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability… | ||
| CVE-2019-20481 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2020 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480. | ||
| CVE-2014-3879 | Cri | 0.64 | 9.8 | 0.03 | Feb 18, 2020 | OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login… | ||
| CVE-2019-20046 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2020 | The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is… | ||
| CVE-2020-8953 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2020 | OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication). | ||
| CVE-2019-20062 | Cri | 0.64 | 9.8 | 0.02 | Feb 10, 2020 | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used). | ||
| CVE-2013-3091 | Cri | 0.64 | 9.8 | 0.04 | Feb 7, 2020 | An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging." | ||
| CVE-2020-8591 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. | ||
| CVE-2020-8510 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password. | ||
| CVE-2013-3317 | Cri | 0.64 | 9.8 | 0.05 | Jan 29, 2020 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. | ||
| CVE-2013-3316 | Cri | 0.64 | 9.8 | 0.05 | Jan 29, 2020 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". | ||
| CVE-2013-3071 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2020 | NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass. | ||
| CVE-2019-15585 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2020 | Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account. | ||
| CVE-2020-7995 | Cri | 0.64 | 9.8 | 0.05 | Jan 26, 2020 | The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts. | ||
| CVE-2012-6451 | Cri | 0.64 | 9.8 | 0.03 | Jan 24, 2020 | Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability | ||
| CVE-2012-2714 | Cri | 0.64 | 9.8 | 0.03 | Jan 9, 2020 | The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier. | ||
| CVE-2014-2651 | Cri | 0.64 | 9.8 | 0.02 | Jan 9, 2020 | Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface |
- risk 0.64cvss 9.8epss 0.01
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the MYKEY substring.
- risk 0.64cvss 9.8epss 0.02
This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSH port…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an…
- risk 0.64cvss 9.8epss 0.02
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability…
- risk 0.64cvss 9.8epss 0.01
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.
- risk 0.64cvss 9.8epss 0.03
OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login…
- risk 0.64cvss 9.8epss 0.02
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is…
- risk 0.64cvss 9.8epss 0.01
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
- risk 0.64cvss 9.8epss 0.02
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
- risk 0.64cvss 9.8epss 0.04
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
- risk 0.64cvss 9.8epss 0.01
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
- risk 0.64cvss 9.8epss 0.05
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
- risk 0.64cvss 9.8epss 0.05
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
- risk 0.64cvss 9.8epss 0.02
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
- risk 0.64cvss 9.8epss 0.02
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.
- risk 0.64cvss 9.8epss 0.05
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
- risk 0.64cvss 9.8epss 0.03
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
- risk 0.64cvss 9.8epss 0.03
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.
- risk 0.64cvss 9.8epss 0.02
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface