VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 54 of 255
  • CVE-2023-2586CriMay 22, 2023
    risk 0.59cvss 9.0epss 0.01

    Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then an attacker could register…

  • CVE-2023-25957CriMar 14, 2023
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.1.9 < V3.3.1), Mendix SAML…

  • CVE-2023-23460CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.

  • CVE-2020-22657CriJan 20, 2023
    risk 0.59cvss 9.1epss 0.01

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2023-22964CriJan 20, 2023
    risk 0.59cvss 9.1epss 0.02

    Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.

  • CVE-2022-36133CriNov 25, 2022
    risk 0.59cvss 9.1epss 0.01

    The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.

  • CVE-2022-41436CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.html.

  • CVE-2022-25652CriSep 16, 2022
    risk 0.59cvss 9.0epss 0.00

    Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking

  • CVE-2022-31013CriMay 31, 2022
    risk 0.59cvss 9.1epss 0.01

    Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAccessKey` is an async function, as the code…

  • CVE-2022-26034CriApr 15, 2022
    risk 0.59cvss 9.1epss 0.01

    Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00, and B/M9000 VP R8.01.01 to R8.03.01 allows an attacker to…

  • CVE-2022-25157CriApr 1, 2022
    risk 0.59cvss 9.1epss 0.02

    Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions,…

  • CVE-2022-23383CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.01

    YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home…

  • CVE-2022-0492HigKEVMar 3, 2022
    risk 0.59cvss 7.8epss 0.06

    A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation…

  • CVE-2021-43834CriDec 16, 2021
    risk 0.59cvss 9.1epss 0.01

    eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It…

  • CVE-2021-21399CriApr 13, 2021
    risk 0.59cvss 9.1epss 0.01

    Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For…

  • CVE-2021-21982CriApr 1, 2021
    risk 0.59cvss 9.1epss 0.01

    VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token.…

  • CVE-2020-7378CriNov 24, 2020
    risk 0.59cvss 9.1epss 0.03

    CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was…

  • CVE-2019-20933CriNov 19, 2020
    risk 0.59cvss 9.8epss 0.31

    InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

  • CVE-2020-15243CriOct 8, 2020
    risk 0.59cvss 9.1epss 0.01

    Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x…

  • CVE-2020-7293CriSep 15, 2020
    risk 0.59cvss 9.0epss 0.01

    Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface.