VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 44 of 241
  • CVE-2025-58443CriSep 6, 2025
    risk 0.61cvss 9.1epss 0.19

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without…

  • CVE-2025-56752CriSep 3, 2025
    risk 0.61cvss 9.4epss 0.01

    A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted…

  • CVE-2025-3659CriMay 12, 2025
    risk 0.61cvss epss 0.00

    Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including…

  • CVE-2024-43240CriAug 19, 2024
    risk 0.61cvss 9.4epss 0.01

    Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

  • CVE-2024-7395CriAug 5, 2024
    risk 0.61cvss epss 0.01

    An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.

  • CVE-2023-6768CriDec 20, 2023
    risk 0.61cvss 9.4epss 0.01

    Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to access the admin panel without providing any credentials by simply accessing the "lp_admin.php?adminstep=" parameter.

  • CVE-2023-1935CriAug 2, 2023
    risk 0.61cvss 9.4epss 0.01

    ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.

  • CVE-2023-25131CriApr 24, 2023
    risk 0.61cvss 9.4epss 0.01

    Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for…

  • CVE-2022-23555CriDec 28, 2022
    risk 0.61cvss 9.4epss 0.01

    authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow…

  • CVE-2022-34379CriSep 1, 2022
    risk 0.61cvss 9.4epss 0.01

    Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized access to the system.

  • CVE-2021-43116HigJul 5, 2022
    risk 0.61cvss 8.8epss 0.07

    An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.

  • CVE-2021-30317CriFeb 11, 2022
    risk 0.61cvss 9.3epss 0.01

    Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2021-21965CriFeb 4, 2022
    risk 0.61cvss 9.3epss 0.01

    A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2020-8193MedKEVJul 10, 2020
    risk 0.61cvss 6.5epss 0.88

    Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

  • CVE-2013-7051HigFeb 4, 2020
    risk 0.61cvss 8.8epss 0.16

    D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

  • CVE-2013-4863HigJan 28, 2020
    risk 0.61cvss 8.8epss 0.12

    The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a…

  • CVE-2019-7666HigJul 1, 2019
    risk 0.61cvss 8.8epss 0.15

    Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.

  • CVE-2018-14786CriAug 23, 2018
    risk 0.61cvss 9.4epss 0.03

    Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper authentication vulnerability where the software does not perform authentication for functionality…

  • CVE-2018-12613HigJun 21, 2018
    risk 0.61cvss 8.8epss 0.98

    An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for…

  • CVE-2017-14000CriOct 5, 2017
    risk 0.61cvss 9.4epss 0.02

    An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the application without authenticating.