VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,803)

page 7 of 241
  • CVE-2024-57045CriFeb 18, 2025
    risk 0.66cvss 9.8epss 0.32

    A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

  • CVE-2024-28255CriMar 15, 2024
    risk 0.66cvss 9.8epss 0.73

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request…

  • CVE-2024-21899CriMar 8, 2024
    risk 0.66cvss 9.8epss 0.24

    An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-20238CriSep 6, 2023
    risk 0.66cvss 10.0epss 0.15

    A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This…

  • CVE-2021-32648HigKEVAug 26, 2021
    risk 0.66cvss 8.2epss 0.90

    octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472…

  • CVE-2021-25281CriFeb 27, 2021
    risk 0.66cvss 9.8epss 0.73

    An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.

  • CVE-2020-9480CriJun 23, 2020
    risk 0.66cvss 9.8epss 0.29

    In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the…

  • CVE-2020-11989CriJun 22, 2020
    risk 0.66cvss 9.8epss 0.24

    Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

  • CVE-2020-1957CriMar 25, 2020
    risk 0.66cvss 9.8epss 0.23

    Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

  • CVE-2015-6922CriFeb 17, 2020
    risk 0.66cvss 9.8epss 0.82

    Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted…

  • CVE-2019-19825CriJan 27, 2020
    risk 0.66cvss 9.8epss 0.30

    On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The…

  • CVE-2026-19977CriAug 17, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit…

  • CVE-2026-59500CriAug 13, 2026
    risk 0.65cvss 10.0epss 0.00

    CWE-287: Improper Authentication

  • CVE-2024-27253CriAug 12, 2026
    risk 0.65cvss 10.0epss 0.00

    IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

  • CVE-2026-56162CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62825CriJul 24, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-45480CriJun 19, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-46389CriJun 5, 2026
    risk 0.65cvss 10.0epss 0.00

    UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the `client-kubernetes-secret` Keycloak client authenticator (shipped by…

  • CVE-2026-46840CriMay 28, 2026
    risk 0.65cvss 10.0epss 0.01

    Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. While…

  • CVE-2026-47280CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.