VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 50 of 255
  • CVE-2016-4510CriJun 9, 2016
    risk 0.61cvss 9.1epss 0.20

    The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitrary files via unspecified vectors.

  • CVE-2013-7137CriJan 26, 2014
    risk 0.61cvss 9.8epss 0.16

    The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.

  • CVE-2026-8979CriMay 28, 2026
    risk 0.60cvss —epss 0.01

    The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST request to the /operator/operator endpoint.

  • CVE-2026-47202CriMay 26, 2026
    risk 0.60cvss —epss 0.00

    Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username. This vulnerability is fixed in 0.9.0.2.

  • CVE-2025-3222CriNov 7, 2025
    risk 0.60cvss —epss 0.00

    Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.

  • CVE-2025-41064CriOct 2, 2025
    risk 0.60cvss —epss 0.00

    Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as an authentication method.

  • CVE-2025-53778HigAug 12, 2025
    risk 0.60cvss 8.8epss 0.48

    Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-22375CriApr 10, 2025
    risk 0.60cvss —epss 0.01

    An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a valid session without any credentials. This vulnerability has been patched in versions later than 9.5 and a patch has been made…

  • CVE-2024-5805CriJun 25, 2024
    risk 0.60cvss 9.1epss 0.07

    Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0.

  • CVE-2024-36266CriJun 11, 2024
    risk 0.60cvss 9.3epss 0.00

    A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local attacker to bypass authentication, thereby gaining administrative privileges for the managed…

  • CVE-2023-42662CriMar 7, 2024
    risk 0.60cvss 9.3epss 0.00

    JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO…

  • CVE-2023-22501CriFeb 1, 2023
    risk 0.60cvss 9.1epss 0.16

    An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and…

  • CVE-2022-34380CriSep 1, 2022
    risk 0.60cvss 9.3epss 0.00

    Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console.…

  • CVE-2022-0715CriMar 9, 2022
    risk 0.60cvss 9.1epss 0.06

    A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior…

  • CVE-2021-37580CriNov 16, 2021
    risk 0.60cvss 9.8epss 0.42

    A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0

  • CVE-2020-11301CriSep 8, 2021
    risk 0.60cvss 9.1epss 0.11

    Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2020-11264CriSep 8, 2021
    risk 0.60cvss 9.1epss 0.13

    Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2020-28050CriMar 5, 2021
    risk 0.60cvss 9.1epss 0.05

    Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.

  • CVE-2019-1917CriJul 17, 2019
    risk 0.60cvss 9.1epss 0.05

    A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this…

  • CVE-2026-75878CriSep 18, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.