CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,090)
page 34 of 255| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20062 | Cri | 0.64 | 9.8 | 0.02 | Feb 10, 2020 | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used). | ||
| CVE-2013-3091 | Cri | 0.64 | 9.8 | 0.04 | Feb 7, 2020 | An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging." | ||
| CVE-2020-8591 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. | ||
| CVE-2020-8510 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password. | ||
| CVE-2013-3317 | Cri | 0.64 | 9.8 | 0.05 | Jan 29, 2020 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. | ||
| CVE-2013-3316 | Cri | 0.64 | 9.8 | 0.05 | Jan 29, 2020 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". | ||
| CVE-2013-3071 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2020 | NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass. | ||
| CVE-2019-15585 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2020 | Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account. | ||
| CVE-2020-7995 | Cri | 0.64 | 9.8 | 0.05 | Jan 26, 2020 | The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts. | ||
| CVE-2012-6451 | Cri | 0.64 | 9.8 | 0.03 | Jan 24, 2020 | Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability | ||
| CVE-2012-2714 | Cri | 0.64 | 9.8 | 0.03 | Jan 9, 2020 | The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier. | ||
| CVE-2014-2651 | Cri | 0.64 | 9.8 | 0.02 | Jan 9, 2020 | Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface | ||
| CVE-2019-19518 | Cri | 0.64 | 9.8 | 0.03 | Jan 8, 2020 | CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands. | ||
| CVE-2013-5122 | Cri | 0.64 | 9.8 | 0.04 | Jan 7, 2020 | Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access | ||
| CVE-2013-4621 | Cri | 0.64 | 9.8 | 0.02 | Dec 27, 2019 | Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities | ||
| CVE-2013-3088 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2019 | Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging". | ||
| CVE-2013-3085 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2019 | An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2. | ||
| CVE-2019-16327 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2019 | D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product. | ||
| CVE-2019-18337 | Cri | 0.64 | 9.8 | 0.03 | Dec 12, 2019 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. A remote… | ||
| CVE-2019-18315 | Cri | 0.64 | 9.8 | 0.02 | Dec 12, 2019 | A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an… |
- risk 0.64cvss 9.8epss 0.02
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
- risk 0.64cvss 9.8epss 0.04
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
- risk 0.64cvss 9.8epss 0.01
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
- risk 0.64cvss 9.8epss 0.05
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
- risk 0.64cvss 9.8epss 0.05
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
- risk 0.64cvss 9.8epss 0.02
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
- risk 0.64cvss 9.8epss 0.02
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.
- risk 0.64cvss 9.8epss 0.05
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
- risk 0.64cvss 9.8epss 0.03
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
- risk 0.64cvss 9.8epss 0.03
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.
- risk 0.64cvss 9.8epss 0.02
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
- risk 0.64cvss 9.8epss 0.03
CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.04
Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access
- risk 0.64cvss 9.8epss 0.02
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
- risk 0.64cvss 9.8epss 0.02
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
- risk 0.64cvss 9.8epss 0.02
An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.
- risk 0.64cvss 9.8epss 0.03
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. A remote…
- risk 0.64cvss 9.8epss 0.02
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an…