VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 34 of 255
  • CVE-2019-20062CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.02

    MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

  • CVE-2013-3091CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.04

    An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

  • CVE-2020-8591CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.

  • CVE-2020-8510CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.

  • CVE-2013-3317CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.05

    Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.

  • CVE-2013-3316CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.05

    Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".

  • CVE-2013-3071CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.02

    NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.

  • CVE-2019-15585CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

  • CVE-2020-7995CriJan 26, 2020
    risk 0.64cvss 9.8epss 0.05

    The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

  • CVE-2012-6451CriJan 24, 2020
    risk 0.64cvss 9.8epss 0.03

    Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability

  • CVE-2012-2714CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.03

    The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.

  • CVE-2014-2651CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.02

    Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface

  • CVE-2019-19518CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.03

    CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.

  • CVE-2013-5122CriJan 7, 2020
    risk 0.64cvss 9.8epss 0.04

    Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access

  • CVE-2013-4621CriDec 27, 2019
    risk 0.64cvss 9.8epss 0.02

    Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities

  • CVE-2013-3088CriDec 26, 2019
    risk 0.64cvss 9.8epss 0.02

    Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

  • CVE-2013-3085CriDec 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.

  • CVE-2019-16327CriDec 26, 2019
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.

  • CVE-2019-18337CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. A remote…

  • CVE-2019-18315CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an…