VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 69 of 253
  • CVE-2014-9753CriFeb 11, 2020
    risk 0.57cvss 9.8epss 0.03

    confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.

  • CVE-2012-3462HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.02

    A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

  • CVE-2019-5486HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.02

    A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

  • CVE-2019-8634HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.01

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged in to another user’s account.

  • CVE-2014-8650CriDec 15, 2019
    risk 0.57cvss 9.8epss 0.04

    python-requests-Kerberos through 0.5 does not handle mutual authentication

  • CVE-2013-2159CriDec 10, 2019
    risk 0.57cvss 9.8epss 0.03

    Monkey HTTP Daemon: broken user name authentication

  • CVE-2019-19598HigDec 5, 2019
    risk 0.57cvss 8.8epss 0.04

    D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used to determine the time when the user sent the request. If…

  • CVE-2019-5218HigNov 29, 2019
    risk 0.57cvss 8.8epss 0.00

    There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.

  • CVE-2019-5233HigNov 13, 2019
    risk 0.57cvss 8.8epss 0.01

    Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.

  • CVE-2019-8149CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.02

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.

  • CVE-2019-12405CriSep 9, 2019
    risk 0.57cvss 9.8epss 0.03

    Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without…

  • CVE-2019-13526HigAug 30, 2019
    risk 0.57cvss 8.8epss 0.02

    Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-13423HigAug 23, 2019
    risk 0.57cvss 8.8epss 0.01

    Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all of the following conditions a-c are true: a) Kibana is configured to use…

  • CVE-2019-14432HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.02

    Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods in which a user is recording a video with the application.…

  • CVE-2016-10826HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).

  • CVE-2018-17213HigJul 29, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform…

  • CVE-2019-5964HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operate the product via unspecified vectors.

  • CVE-2019-2018HigJun 19, 2019
    risk 0.57cvss 8.8epss 0.01

    In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause. Remote user interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-110172241

  • CVE-2018-18877HigJun 18, 2019
    risk 0.57cvss 8.8epss 0.02

    In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.

  • CVE-2019-1724HigMay 3, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. An attacker could use…