VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 70 of 253
  • CVE-2018-16219HigApr 25, 2019
    risk 0.57cvss 8.8epss 0.01

    A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same network as the device) to change the admin password without authentication via a POST request.

  • CVE-2019-11234CriApr 22, 2019
    risk 0.57cvss 9.8epss 0.08

    FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.

  • CVE-2019-10643CriApr 17, 2019
    risk 0.57cvss 9.8epss 0.01

    Contao 4.7 allows Use of a Key Past its Expiration Date.

  • CVE-2019-10884HigApr 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for usersite.example.com. This could lead to successful phishing…

  • CVE-2019-5890HigApr 1, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and execute administrative functions.

  • CVE-2018-19023HigJan 25, 2019
    risk 0.57cvss 8.8epss 0.01

    Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.

  • CVE-2018-18814HigJan 16, 2019
    risk 0.57cvss 8.8epss 0.03

    The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the authentication that theoretically may allow an attacker to gain full access to a…

  • CVE-2018-0676HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management screen and execute an arbitrary command via unspecified vectors.

  • CVE-2018-15751CriOct 24, 2018
    risk 0.57cvss 9.8epss 0.05

    SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).

  • CVE-2018-18389CriOct 16, 2018
    risk 0.57cvss 9.8epss 0.02

    Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.

  • CVE-2018-15152CriAug 15, 2018
    risk 0.57cvss 9.1epss 0.26

    Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5)…

  • CVE-2018-3775HigAug 12, 2018
    risk 0.57cvss 8.8epss 0.01

    Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.

  • CVE-2017-2652HigJul 27, 2018
    risk 0.57cvss 8.8epss 0.01

    It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary…

  • CVE-2016-9497HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.02

    Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible via telnet and does not require authentication. An unauthenticated remote user…

  • CVE-2016-6541HigJul 6, 2018
    risk 0.57cvss 8.8epss 0.01

    TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in…

  • CVE-2018-11407CriJun 13, 2018
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an…

  • CVE-2018-7943HigJun 5, 2018
    risk 0.57cvss 8.8epss 0.01

    There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information…

  • CVE-2018-7949HigJun 1, 2018
    risk 0.57cvss 8.8epss 0.01

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables…

  • CVE-2018-11478HigMay 30, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands to the car (different for every vendor / car product line /…

  • CVE-2016-10525CriMay 29, 2018
    risk 0.57cvss 9.8epss 0.03

    When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.