VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 63 of 253
  • CVE-2024-5201HigMay 23, 2024
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user via HTTP Request

  • CVE-2023-41956HigMay 17, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.

  • CVE-2024-4129HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0.

  • CVE-2024-4303HigApr 29, 2024
    risk 0.57cvss 8.8epss 0.01

    ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentials can bypass MFA, allowing them to successfully log into the APP.

  • CVE-2024-29837HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.

  • CVE-2024-24279HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.

  • CVE-2024-2450HigMar 15, 2024
    risk 0.57cvss 8.8epss 0.01

    Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted…

  • CVE-2024-0568HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.00

    CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.

  • CVE-2024-25313HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.

  • CVE-2023-51982CriJan 30, 2024
    risk 0.57cvss 9.8epss 0.01

    CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and…

  • CVE-2023-40038HigDec 27, 2023
    risk 0.57cvss 8.8epss 0.00

    Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)

  • CVE-2023-44252HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with crafted JWT token…

  • CVE-2023-6514HigDec 6, 2023
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.  Successful exploitation of this vulnerability may allow attackers…

  • CVE-2023-5970HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.

  • CVE-2022-41678HigNov 28, 2023
    risk 0.57cvss 8.8epss 0.86

    Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able…

  • CVE-2023-48312CriNov 24, 2023
    risk 0.57cvss 9.8epss 0.01

    capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated based on the `TokenReview` result. All the clusters running with the…

  • CVE-2023-35794HigOct 27, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication…

  • CVE-2023-43961HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

  • CVE-2023-5246HigOct 23, 2023
    risk 0.57cvss 8.8epss 0.01

    Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the…

  • CVE-2023-42771HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.00

    Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload…