CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,056)
page 68 of 253| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15055 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2020 | TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter. | ||
| CVE-2020-13365 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2020 | Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0;… | ||
| CVE-2020-8207 | Hig | 0.57 | 8.8 | 0.02 | Jul 24, 2020 | Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running. | ||
| CVE-2017-18908 | Cri | 0.57 | 9.8 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address. | ||
| CVE-2016-11074 | Cri | 0.57 | 9.8 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused. | ||
| CVE-2018-21263 | Hig | 0.57 | 8.8 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response. | ||
| CVE-2018-21246 | Cri | 0.57 | 9.8 | 0.03 | Jun 15, 2020 | Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode. | ||
| CVE-2020-11551 | Hig | 0.57 | 8.8 | 0.02 | May 18, 2020 | An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote… | ||
| CVE-2017-18720 | Hig | 0.57 | 8.8 | 0.01 | Apr 24, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42. | ||
| CVE-2017-18733 | Hig | 0.57 | 8.8 | 0.01 | Apr 23, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects D6220 before 1.0.0.28, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.8, R6400 before 1.0.1.22, R6400v2 before 1.0.2.32, R7100LG before 1.0.0.32, R7300DST before 1.0.0.52, R8300 before… | ||
| CVE-2017-18732 | Hig | 0.57 | 8.8 | 0.01 | Apr 23, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, PLW1000v2 before 1.0.0.14, and PLW1010v2 before 1.0.0.14. | ||
| CVE-2017-18743 | Hig | 0.57 | 8.8 | 0.01 | Apr 23, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, R6400 before 1.0.1.20, R6700 before 1.0.1.20, R6900 before 1.0.1.20, R7000 before 1.0.7.10, R7100LG before V1.0.0.32, R7300DST before 1.0.0.52, R7900 before 1.0.1.16, R8000 before… | ||
| CVE-2018-21128 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17. | ||
| CVE-2018-21125 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | NETGEAR WAC510 devices before 5.0.0.17 are affected by authentication bypass. | ||
| CVE-2018-21121 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0.6. | ||
| CVE-2018-21118 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | NETGEAR XR500 devices before 2.3.2.32 are affected by authentication bypass. | ||
| CVE-2017-18772 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R7300DST… | ||
| CVE-2019-20786 | Cri | 0.57 | 9.8 | 0.03 | Apr 19, 2020 | handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion. | ||
| CVE-2020-8828 | Hig | 0.57 | 8.8 | 0.02 | Apr 8, 2020 | As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are… | ||
| CVE-2020-5536 | Hig | 0.57 | 8.8 | 0.01 | Mar 4, 2020 | OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentication and to initialize the device via unspecified vectors. |
- risk 0.57cvss 8.8epss 0.01
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
- risk 0.57cvss 8.8epss 0.01
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0;…
- risk 0.57cvss 8.8epss 0.02
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.
- risk 0.57cvss 9.8epss 0.01
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.
- risk 0.57cvss 9.8epss 0.01
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a different user's account via a crafted SAML response.
- risk 0.57cvss 9.8epss 0.03
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote…
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects D6220 before 1.0.0.28, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.8, R6400 before 1.0.1.22, R6400v2 before 1.0.2.32, R7100LG before 1.0.0.32, R7300DST before 1.0.0.52, R8300 before…
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, PLW1000v2 before 1.0.0.14, and PLW1010v2 before 1.0.0.14.
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, R6400 before 1.0.1.20, R6700 before 1.0.1.20, R6900 before 1.0.1.20, R7000 before 1.0.7.10, R7100LG before V1.0.0.32, R7300DST before 1.0.0.52, R7900 before 1.0.1.16, R8000 before…
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.
- risk 0.57cvss 8.8epss 0.01
NETGEAR WAC510 devices before 5.0.0.17 are affected by authentication bypass.
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0.6.
- risk 0.57cvss 8.8epss 0.01
NETGEAR XR500 devices before 2.3.2.32 are affected by authentication bypass.
- risk 0.57cvss 8.8epss 0.01
Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R7300DST…
- risk 0.57cvss 9.8epss 0.03
handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion.
- risk 0.57cvss 8.8epss 0.02
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are…
- risk 0.57cvss 8.8epss 0.01
OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentication and to initialize the device via unspecified vectors.