VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 63 of 241
  • CVE-2017-18772HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R7300DST…

  • CVE-2019-20786CriApr 19, 2020
    risk 0.57cvss 9.8epss 0.03

    handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion.

  • CVE-2020-8828HigApr 8, 2020
    risk 0.57cvss 8.8epss 0.02

    As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are…

  • CVE-2020-5536HigMar 4, 2020
    risk 0.57cvss 8.8epss 0.01

    OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentication and to initialize the device via unspecified vectors.

  • CVE-2014-9753CriFeb 11, 2020
    risk 0.57cvss 9.8epss 0.03

    confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.

  • CVE-2012-3462HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.02

    A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

  • CVE-2019-5486HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.02

    A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

  • CVE-2019-8634HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.01

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged in to another user’s account.

  • CVE-2014-8650CriDec 15, 2019
    risk 0.57cvss 9.8epss 0.04

    python-requests-Kerberos through 0.5 does not handle mutual authentication

  • CVE-2013-2159CriDec 10, 2019
    risk 0.57cvss 9.8epss 0.03

    Monkey HTTP Daemon: broken user name authentication

  • CVE-2019-19598HigDec 5, 2019
    risk 0.57cvss 8.8epss 0.04

    D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used to determine the time when the user sent the request. If…

  • CVE-2019-5218HigNov 29, 2019
    risk 0.57cvss 8.8epss 0.00

    There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.

  • CVE-2019-5233HigNov 13, 2019
    risk 0.57cvss 8.8epss 0.01

    Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.

  • CVE-2019-8149CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.02

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.

  • CVE-2019-12405CriSep 9, 2019
    risk 0.57cvss 9.8epss 0.03

    Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without…

  • CVE-2019-13526HigAug 30, 2019
    risk 0.57cvss 8.8epss 0.02

    Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-13423HigAug 23, 2019
    risk 0.57cvss 8.8epss 0.01

    Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all of the following conditions a-c are true: a) Kibana is configured to use…

  • CVE-2019-14432HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.02

    Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods in which a user is recording a video with the application.…

  • CVE-2016-10826HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).

  • CVE-2018-17213HigJul 29, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform…