VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 47 of 241
  • CVE-2025-45583CriSep 12, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.

  • CVE-2025-55234HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.20

    SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for…

  • CVE-2025-54918HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.19

    Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-21450CriJul 8, 2025
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue occurs due to use of insecure connection method while downloading.

  • CVE-2025-30282CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass…

  • CVE-2025-31122CriMar 31, 2025
    risk 0.59cvss epss 0.00

    scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to login to any account by changing the username in the username field.

  • CVE-2025-30114CriMar 18, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can…

  • CVE-2024-48859CriDec 6, 2024
    risk 0.59cvss 9.1epss 0.01

    An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions:…

  • CVE-2024-38124CriOct 8, 2024
    risk 0.59cvss 9.0epss 0.01

    Windows Netlogon Elevation of Privilege Vulnerability

  • CVE-2024-6235HigJul 10, 2024
    risk 0.59cvss 8.8epss 0.21

    Sensitive information disclosure in NetScaler Console

  • CVE-2024-28200CriJul 1, 2024
    risk 0.59cvss 9.1epss 0.02

    The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any…

  • CVE-2023-43551CriJun 3, 2024
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.

  • CVE-2024-34340CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls…

  • CVE-2024-33110CriMay 6, 2024
    risk 0.59cvss 9.1epss 0.01

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.

  • CVE-2023-44039CriApr 3, 2024
    risk 0.59cvss 9.1epss 0.01

    In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register their FIDO authenticator to a victim’s account and consequently take over the account.

  • CVE-2024-25106CriFeb 8, 2024
    risk 0.59cvss 9.1epss 0.00

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user…

  • CVE-2023-6483CriDec 18, 2023
    risk 0.59cvss 9.1epss 0.01

    The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the ADiTaaS backend API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP…

  • CVE-2023-33054CriDec 5, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.

  • CVE-2023-4562CriOct 13, 2023
    risk 0.59cvss 9.1epss 0.01

    Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication…

  • CVE-2023-28540CriOct 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in Data Modem due to improper authentication during TLS handshake.