VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 35 of 255
  • CVE-2019-18314CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted objects via RMI. Please note that an attacker…

  • CVE-2019-18284CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exposed via this interface to receive password hashes of other…

  • CVE-2019-14910CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

  • CVE-2019-19521CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.03

    libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).

  • CVE-2019-12394CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.

  • CVE-2019-6675CriNov 26, 2019
    risk 0.64cvss 9.8epss 0.01

    BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. This issue only…

  • CVE-2019-18250CriNov 26, 2019
    risk 0.64cvss 9.8epss 0.02

    In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.

  • CVE-2019-18374CriNov 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authentication controls.

  • CVE-2013-3072CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.02

    An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration…

  • CVE-2013-3367CriNov 13, 2019
    risk 0.64cvss 9.8epss 0.03

    Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.

  • CVE-2011-4628CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.

  • CVE-2016-2359CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.03

    Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource.

  • CVE-2019-9531CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.03

    The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT) commands, including some that provide…

  • CVE-2019-13336CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.03

    The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arbitrary values. NOTE: the vendor's position is that this…

  • CVE-2019-11733CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.01

    When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering…

  • CVE-2019-16190CriSep 9, 2019
    risk 0.64cvss 9.8epss 0.03

    SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.

  • CVE-2019-13188CriSep 5, 2019
    risk 0.64cvss 9.8epss 0.02

    In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.

  • CVE-2019-11064CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1…

  • CVE-2014-10389CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

  • CVE-2019-1974CriAug 21, 2019
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an…