VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 43 of 241
  • CVE-2024-23470CriJul 17, 2024
    risk 0.62cvss 9.6epss 0.01

    The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables.

  • CVE-2023-47222CriApr 26, 2024
    risk 0.62cvss 9.6epss 0.01

    An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version:…

  • CVE-2024-23629CriJan 26, 2024
    risk 0.62cvss 9.6epss 0.01

    An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.

  • CVE-2023-28727CriMar 31, 2023
    risk 0.62cvss 9.6epss 0.00

    Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers.

  • CVE-2022-4126CriMar 27, 2023
    risk 0.62cvss 9.6epss 0.01

    Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects RCCMD: before 4.40 230207.

  • CVE-2022-2662CriAug 16, 2022
    risk 0.62cvss 9.6epss 0.01

    Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access to the device.

  • CVE-2022-31125CriJul 6, 2022
    risk 0.62cvss 10.0epss 0.20

    Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This…

  • CVE-2021-28494CriSep 9, 2021
    risk 0.62cvss 9.6epss 0.01

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior…

  • CVE-2021-22943CriAug 31, 2021
    risk 0.62cvss 9.6epss 0.00

    A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vulnerability is fixed in UniFi Protect application V1.19.0…

  • CVE-2020-13292CriAug 10, 2020
    risk 0.62cvss 9.6epss 0.01

    In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

  • CVE-2018-10933CriOct 17, 2018
    risk 0.62cvss 9.1epss 0.92

    A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

  • CVE-2018-7750CriMar 13, 2018
    risk 0.62cvss 9.8epss 0.27

    transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing…

  • CVE-2026-50561CriAug 12, 2026
    risk 0.61cvss 9.4epss 0.00

    Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the…

  • CVE-2026-41679CriApr 23, 2026
    risk 0.61cvss 10.0epss 0.03

    Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with…

  • CVE-2025-70833CriFeb 20, 2026
    risk 0.61cvss 9.4epss 0.00

    An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from insecure permission validation in…

  • CVE-2025-67822CriJan 15, 2026
    risk 0.61cvss 9.4epss 0.00

    A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could…

  • CVE-2025-68717CriJan 8, 2026
    risk 0.61cvss 9.4epss 0.01

    KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers…

  • CVE-2026-21891CriJan 8, 2026
    risk 0.61cvss 9.4epss 0.02

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided…

  • CVE-2025-9965CriSep 23, 2025
    risk 0.61cvss epss 0.01

    Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

  • CVE-2025-10365CriSep 12, 2025
    risk 0.61cvss epss 0.06

    The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and…