VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 59 of 241
  • CVE-2023-0228HigMar 2, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.

  • CVE-2022-45922HigJan 18, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie,…

  • CVE-2023-0311CriJan 15, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

  • CVE-2022-47209HigDec 16, 2022
    risk 0.57cvss 8.8epss 0.00

    A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.

  • CVE-2022-40966HigDec 7, 2022
    risk 0.57cvss 8.8epss 0.00

    Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and…

  • CVE-2022-44620HigDec 7, 2022
    risk 0.57cvss 8.8epss 0.01

    Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.

  • CVE-2022-46411HigDec 4, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.

  • CVE-2022-36960HigNov 29, 2022
    risk 0.57cvss 8.8epss 0.01

    SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.

  • CVE-2021-45036HigNov 28, 2022
    risk 0.57cvss 8.7epss 0.01

    Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.

  • CVE-2022-43685HigNov 22, 2022
    risk 0.57cvss 8.8epss 0.01

    CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.

  • CVE-2022-26845HigNov 11, 2022
    risk 0.57cvss 8.7epss 0.01

    Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-39038HigNov 10, 2022
    risk 0.57cvss 8.8epss 0.01

    Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.

  • CVE-2022-39366CriOct 28, 2022
    risk 0.57cvss 9.9epss 0.01

    DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user if Metadata Service…

  • CVE-2022-37298CriOct 20, 2022
    risk 0.57cvss 9.8epss 0.02

    Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring…

  • CVE-2022-35135HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.01

    Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/.

  • CVE-2022-35248HigSep 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when telling the server to use CAS during login.

  • CVE-2022-36436CriSep 14, 2022
    risk 0.57cvss 9.8epss 0.02

    OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability that could allow a malicious actor to gain unauthorized access to a VNC session or to disconnect a legitimate user from a VNC…

  • CVE-2022-40622HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the…

  • CVE-2022-38700HigSep 9, 2022
    risk 0.57cvss 8.8epss 0.00

    OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.

  • CVE-2022-2031HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use…