CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,090)
page 53 of 255| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-30114 | Cri | 0.59 | 9.1 | 0.00 | Mar 18, 2025 | An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can… | ||
| CVE-2024-48859 | Cri | 0.59 | 9.1 | 0.01 | Dec 6, 2024 | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions:… | ||
| CVE-2024-38124 | Cri | 0.59 | 9.0 | 0.01 | Oct 8, 2024 | Windows Netlogon Elevation of Privilege Vulnerability | ||
| CVE-2024-6235 | Hig | 0.59 | 8.8 | 0.21 | Jul 10, 2024 | Sensitive information disclosure in NetScaler Console | ||
| CVE-2024-28200 | Cri | 0.59 | 9.1 | 0.02 | Jul 1, 2024 | The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any… | ||
| CVE-2023-43551 | Cri | 0.59 | 9.1 | 0.00 | Jun 3, 2024 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. | ||
| CVE-2024-34340 | Cri | 0.59 | 9.1 | 0.01 | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls… | ||
| CVE-2024-33110 | Cri | 0.59 | 9.1 | 0.01 | May 6, 2024 | D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component. | ||
| CVE-2023-44039 | Cri | 0.59 | 9.1 | 0.01 | Apr 3, 2024 | In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register their FIDO authenticator to a victim’s account and consequently take over the account. | ||
| CVE-2024-25106 | Cri | 0.59 | 9.1 | 0.00 | Feb 8, 2024 | OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user… | ||
| CVE-2023-6483 | Cri | 0.59 | 9.1 | 0.01 | Dec 18, 2023 | The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the ADiTaaS backend API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP… | ||
| CVE-2023-33054 | Cri | 0.59 | 9.1 | 0.00 | Dec 5, 2023 | Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. | ||
| CVE-2023-4562 | Cri | 0.59 | 9.1 | 0.01 | Oct 13, 2023 | Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication… | ||
| CVE-2023-28540 | Cri | 0.59 | 9.1 | 0.00 | Oct 3, 2023 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | ||
| CVE-2023-44152 | Cri | 0.59 | 9.1 | 0.01 | Sep 27, 2023 | Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | ||
| CVE-2023-0773 | Cri | 0.59 | 9.1 | 0.01 | Sep 19, 2023 | The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation… | ||
| CVE-2023-40260 | Cri | 0.59 | 9.1 | 0.01 | Aug 11, 2023 | EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's email address, and the product would then send MFA codes… | ||
| CVE-2023-20214 | Cri | 0.59 | 9.1 | 0.01 | Aug 3, 2023 | A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. … | ||
| CVE-2023-29129 | Cri | 0.59 | 9.1 | 0.01 | Jun 13, 2023 | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.4.0), Mendix SAML (Mendix 8… | ||
| CVE-2023-3065 | Cri | 0.59 | 9.1 | 0.01 | Jun 5, 2023 | Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile application AMXGT100 through 1.3.20. |
- risk 0.59cvss 9.1epss 0.00
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can…
- risk 0.59cvss 9.1epss 0.01
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following versions:…
- risk 0.59cvss 9.0epss 0.01
Windows Netlogon Elevation of Privilege Vulnerability
- risk 0.59cvss 8.8epss 0.21
Sensitive information disclosure in NetScaler Console
- risk 0.59cvss 9.1epss 0.02
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any…
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
- risk 0.59cvss 9.1epss 0.01
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls…
- risk 0.59cvss 9.1epss 0.01
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
- risk 0.59cvss 9.1epss 0.01
In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register their FIDO authenticator to a victim’s account and consequently take over the account.
- risk 0.59cvss 9.1epss 0.00
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user…
- risk 0.59cvss 9.1epss 0.01
The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the ADiTaaS backend API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP…
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
- risk 0.59cvss 9.1epss 0.01
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication…
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
- risk 0.59cvss 9.1epss 0.01
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- risk 0.59cvss 9.1epss 0.01
The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation…
- risk 0.59cvss 9.1epss 0.01
EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's email address, and the product would then send MFA codes…
- risk 0.59cvss 9.1epss 0.01
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. …
- risk 0.59cvss 9.1epss 0.01
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.4.0), Mendix SAML (Mendix 8…
- risk 0.59cvss 9.1epss 0.01
Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile application AMXGT100 through 1.3.20.