VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 64 of 253
  • CVE-2023-29463HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.01

    The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session data and or log users out of their session.

  • CVE-2023-37284HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication.

  • CVE-2023-38585HigAug 23, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H,…

  • CVE-2023-33237HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.01

    TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-privileged APIs to execute restricted actions that only…

  • CVE-2023-33563HigAug 1, 2023
    risk 0.57cvss 8.8epss 0.01

    In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-38555HigJul 26, 2023
    risk 0.57cvss 8.8epss 0.00

    Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B…

  • CVE-2022-34155HigJul 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.

  • CVE-2023-37266CriJul 17, 2023
    risk 0.57cvss 9.8epss 0.07

    CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs…

  • CVE-2023-33190CriJun 29, 2023
    risk 0.57cvss 9.9epss 0.01

    Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper configuration of role based access control (RBAC) permissions resulted in an attacker being able to obtain cluster control…

  • CVE-2023-32524HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.03

    Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-32523HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.03

    Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute…

  • CVE-2023-34340CriJun 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials are provided. Users are advised to…

  • CVE-2023-25946HigMay 23, 2023
    risk 0.57cvss 8.8epss 0.00

    Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product's communication data and conduct an arbitrary operation under certain conditions.

  • CVE-2023-0863HigMay 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC…

  • CVE-2022-43620HigMar 29, 2023
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue…

  • CVE-2023-28609CriMar 18, 2023
    risk 0.57cvss 9.8epss 0.01

    api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.

  • CVE-2023-0228HigMar 2, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.

  • CVE-2022-45922HigJan 18, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie,…

  • CVE-2023-0311CriJan 15, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

  • CVE-2022-47209HigDec 16, 2022
    risk 0.57cvss 8.8epss 0.00

    A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.