VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 49 of 241
  • CVE-2021-21399CriApr 13, 2021
    risk 0.59cvss 9.1epss 0.01

    Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For…

  • CVE-2021-21982CriApr 1, 2021
    risk 0.59cvss 9.1epss 0.01

    VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token.…

  • CVE-2020-7378CriNov 24, 2020
    risk 0.59cvss 9.1epss 0.03

    CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was…

  • CVE-2019-20933CriNov 19, 2020
    risk 0.59cvss 9.8epss 0.31

    InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

  • CVE-2020-15243CriOct 8, 2020
    risk 0.59cvss 9.1epss 0.01

    Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x…

  • CVE-2020-7293CriSep 15, 2020
    risk 0.59cvss 9.0epss 0.01

    Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface.

  • CVE-2020-25251CriSep 11, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client-side authentication is used for critical functions such as adding users or retrieving sensitive information.

  • CVE-2020-5777CriSep 1, 2020
    risk 0.59cvss 9.8epss 0.23

    MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is…

  • CVE-2020-9233CriAug 17, 2020
    risk 0.59cvss 9.1epss 0.01

    FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to delete some files and cause some services abnormal.

  • CVE-2020-14158CriJul 30, 2020
    risk 0.59cvss 9.1epss 0.02

    The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchanged with an alarm panel. This makes it easier to conduct wAppLoxx authentication-bypass attacks.

  • CVE-2020-6091CriMay 22, 2020
    risk 0.59cvss 9.1epss 0.02

    An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MAIN2: 8X7325WWV303. A specially crafted series of HTTP requests can cause authentication bypass resulting in information disclosure. An…

  • CVE-2020-2018CriMay 13, 2020
    risk 0.59cvss 9.0epss 0.01

    An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management interface to gain privileged access to managed firewalls. An attacker requires some knowledge of managed firewalls to exploit this…

  • CVE-2019-19104CriApr 22, 2020
    risk 0.59cvss 9.1epss 0.01

    The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (URL) , violating the access-control (ACL) rules. This issue…

  • CVE-2019-14880CriMar 31, 2020
    risk 0.59cvss 9.1epss 0.01

    A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

  • CVE-2013-4454CriFeb 18, 2020
    risk 0.59cvss 9.1epss 0.04

    WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities

  • CVE-2014-4198CriFeb 13, 2020
    risk 0.59cvss 9.1epss 0.01

    A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged function.

  • CVE-2013-4462CriJan 27, 2020
    risk 0.59cvss 9.1epss 0.03

    WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability

  • CVE-2019-18322CriDec 12, 2019
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to read and write arbitrary files on the local file system by sending specifically crafted packets to port 5010/tcp. This…

  • CVE-2019-18321CriDec 12, 2019
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to read and write arbitrary files on the local file system by sending specifically crafted packets to port 5010/tcp. This…

  • CVE-2019-15803CriNov 14, 2019
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the password returned by…