VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 61 of 241
  • CVE-2021-22155HigMay 13, 2021
    risk 0.57cvss 8.8epss 0.01

    An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10.1, 9.1 and earlier could allow an attacker to potentially gain access to the application in the context of the targeted user’s…

  • CVE-2021-26077HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the…

  • CVE-2021-27522HigApr 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the initial letter of the key of a user cookie, the key of the administrator cookie can be obtained.

  • CVE-2020-35231HigMar 10, 2021
    risk 0.57cvss 8.8epss 0.01

    The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of the device.

  • CVE-2021-22858HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.01

    Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.

  • CVE-2020-27865HigFeb 12, 2021
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the uhttpd service,…

  • CVE-2021-25863HigJan 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.

  • CVE-2020-27846CriDec 21, 2020
    risk 0.57cvss 9.8epss 0.05

    A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

  • CVE-2020-29378HigNov 29, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. It is possible to elevate the privilege of a CLI user (to full administrative access) by using the password…

  • CVE-2020-26214CriNov 6, 2020
    risk 0.57cvss 9.1epss 0.66

    In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP servers are configured to allow unauthenticated authentication…

  • CVE-2020-17510CriNov 5, 2020
    risk 0.57cvss 9.8epss 0.09

    Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

  • CVE-2020-2301CriNov 4, 2020
    risk 0.57cvss 9.8epss 0.02

    Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode.

  • CVE-2020-2300CriNov 4, 2020
    risk 0.57cvss 9.8epss 0.02

    Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.

  • CVE-2020-2299CriNov 4, 2020
    risk 0.57cvss 9.8epss 0.01

    Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.

  • CVE-2020-7591HigOct 15, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to impersonate other users of the system and perform (potentially administrative) actions on behalf of those users if the single…

  • CVE-2020-8350HigOct 14, 2020
    risk 0.57cvss 8.8epss 0.01

    An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of privilege.

  • CVE-2020-24660CriSep 14, 2020
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.

  • CVE-2020-16222HigSep 11, 2020
    risk 0.57cvss 8.8epss 0.01

    In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.

  • CVE-2020-4662HigAug 14, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 186233.

  • CVE-2020-8713HigAug 13, 2020
    risk 0.57cvss 8.8epss 0.01

    Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.