VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,054)

page 4 of 253
  • CVE-2025-49706MedKEVJul 8, 2025
    risk 0.71cvss 6.5epss 0.99

    Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2024-45216CriOct 16, 2024
    risk 0.71cvss 9.8epss 0.92

    Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests…

  • CVE-2023-50919CriJan 12, 2024
    risk 0.71cvss 9.8epss 0.48

    An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7,…

  • CVE-2023-27823CriMay 12, 2023
    risk 0.71cvss 9.8epss 0.54

    An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.

  • CVE-2023-27482CriMar 8, 2023
    risk 0.71cvss 10.0epss 0.72

    homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1…

  • CVE-2022-0540CriApr 20, 2022
    risk 0.71cvss 9.8epss 0.88

    A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0…

  • CVE-2022-22956CriApr 13, 2022
    risk 0.71cvss 9.8epss 0.50

    VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

  • CVE-2019-6441CriMar 21, 2019
    risk 0.71cvss 9.8epss 0.54

    An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of…

  • CVE-2018-8096CriMar 14, 2018
    risk 0.71cvss 9.8epss 0.48

    Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","Value":false' in an api/settings/setting-isauthenticationenabled PUT request.

  • CVE-2017-6526CriMar 9, 2017
    risk 0.71cvss 9.8epss 0.57

    An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests).

  • CVE-2026-49869CriKEVJun 26, 2026
    risk 0.70cvss 10.0epss 0.02

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather…

  • CVE-2025-1044CriFeb 11, 2025
    risk 0.70cvss 9.8epss 0.75

    Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2023-49105CriKEVNov 21, 2023
    risk 0.70cvss 9.8epss 0.43

    An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted…

  • CVE-2023-34124CriJul 13, 2023
    risk 0.70cvss 9.8epss 0.50

    The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-32243CriMay 12, 2023
    risk 0.70cvss 9.8epss 0.76

    Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

  • CVE-2022-0342CriMar 28, 2022
    risk 0.70cvss 9.8epss 0.95

    An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG…

  • CVE-2021-41303CriSep 17, 2021
    risk 0.70cvss 9.8epss 0.77

    Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

  • CVE-2021-31251CriJun 4, 2021
    risk 0.70cvss 9.8epss 0.36

    An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote…

  • CVE-2013-4976CriDec 27, 2019
    risk 0.70cvss 9.8epss 0.36

    Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials

  • CVE-2019-6814CriMay 22, 2019
    risk 0.70cvss 9.8epss 0.37

    A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.