VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 67 of 241
  • CVE-2026-49202HigJun 4, 2026
    risk 0.56cvss 8.6epss 0.00

    Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.

  • CVE-2026-32173HigApr 3, 2026
    risk 0.56cvss 8.6epss 0.01

    Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-25748HigFeb 12, 2026
    risk 0.56cvss 8.6epss 0.01

    authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy.…

  • CVE-2025-66698HigJan 13, 2026
    risk 0.56cvss 8.6epss 0.00

    An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

  • CVE-2025-11192HigOct 7, 2025
    risk 0.56cvss 8.6epss 0.00

    A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be…

  • CVE-2024-6078HigAug 14, 2024
    risk 0.56cvss epss 0.00

    CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a…

  • CVE-2024-3826HigJul 2, 2024
    risk 0.56cvss epss 0.00

    In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.

  • CVE-2024-5012HigJun 25, 2024
    risk 0.56cvss 8.6epss 0.00

    In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored in the product Credential Library.

  • CVE-2023-38534HigMar 13, 2024
    risk 0.56cvss 8.6epss 0.01

    Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC. 

  • CVE-2023-6451HigFeb 16, 2024
    risk 0.56cvss 8.6epss 0.01

    Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.

  • CVE-2023-5376HigJan 9, 2024
    risk 0.56cvss 8.6epss 0.01

    An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

  • CVE-2023-51708HigDec 22, 2023
    risk 0.56cvss 8.6epss 0.00

    Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and…

  • CVE-2023-3028HigJun 1, 2023
    risk 0.56cvss 8.6epss 0.00

    Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected too. Multiple vulnerabilities were…

  • CVE-2021-45841HigApr 25, 2022
    risk 0.56cvss 8.1epss 0.08

    In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker…

  • CVE-2021-21513HigMar 2, 2021
    risk 0.56cvss 8.6epss 0.06

    Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to…

  • CVE-2020-3944HigFeb 19, 2020
    risk 0.56cvss 8.6epss 0.01

    vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running,…

  • CVE-2018-13990HigMay 6, 2019
    risk 0.56cvss 8.6epss 0.02

    The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.

  • CVE-2019-6521HigFeb 5, 2019
    risk 0.56cvss 8.6epss 0.02

    WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and manipulate sensitive information.

  • CVE-2018-2449HigAug 14, 2018
    risk 0.56cvss 8.6epss 0.02

    SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.

  • CVE-2016-8023HigMar 14, 2017
    risk 0.56cvss 8.1epss 0.09

    Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to bypass server authentication via a crafted authentication cookie.