VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 36 of 255
  • CVE-2019-1938CriAug 21, 2019
    risk 0.64cvss 9.8epss 0.05

    A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The…

  • CVE-2019-11187CriAug 15, 2019
    risk 0.64cvss 9.8epss 0.02

    Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.

  • CVE-2019-14985CriAug 13, 2019
    risk 0.64cvss 9.8epss 0.08

    eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.

  • CVE-2019-7163CriAug 2, 2019
    risk 0.64cvss 9.8epss 0.02

    The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password.

  • CVE-2019-11202CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher…

  • CVE-2019-9629CriJul 8, 2019
    risk 0.64cvss 9.8epss 0.01

    Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).

  • CVE-2018-11426CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute force parameters required to bypass authentication and access the web interface to use all its functions except for password change.

  • CVE-2018-15556CriJun 27, 2019
    risk 0.64cvss 9.8epss 0.03

    The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.

  • CVE-2019-11232CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.

  • CVE-2018-7121CriJun 5, 2019
    risk 0.64cvss 9.8epss 0.08

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-12564CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.02

    In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames.

  • CVE-2019-12530CriJun 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.

  • CVE-2019-12440CriMay 29, 2019
    risk 0.64cvss 9.8epss 0.02

    The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.

  • CVE-2018-11271CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.01

    Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in…

  • CVE-2019-12300CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.02

    Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

  • CVE-2018-7847CriMay 22, 2019
    risk 0.64cvss 9.8epss 0.04

    A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.

  • CVE-2019-3927CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.02

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can use this vulnerability to…

  • CVE-2019-11576CriApr 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.

  • CVE-2019-11081CriApr 24, 2019
    risk 0.64cvss 9.8epss 0.02

    A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative access to the application server.

  • CVE-2019-11018CriApr 8, 2019
    risk 0.64cvss 9.8epss 0.01

    application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change.