VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 70 of 241
  • CVE-2023-25556HigApr 18, 2023
    risk 0.54cvss 8.3epss 0.00

    A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.

  • CVE-2022-44574HigMar 10, 2023
    risk 0.54cvss 7.5epss 0.65

    An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.

  • CVE-2022-35401HigJan 10, 2023
    risk 0.54cvss 8.1epss 0.21

    An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to…

  • CVE-2022-45877HigDec 8, 2022
    risk 0.54cvss 8.3epss 0.00

    OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.

  • CVE-2022-40259HigDec 5, 2022
    risk 0.54cvss 8.3epss 0.01

    MegaRAC Default Credentials Vulnerability

  • CVE-2022-42463HigOct 14, 2022
    risk 0.54cvss 8.3epss 0.00

    OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and…

  • CVE-2022-36071HigSep 2, 2022
    risk 0.54cvss 8.3epss 0.00

    SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a secondary authentication factor. Because TOTPs are often configured on mobile devices that can be lost,…

  • CVE-2022-37397HigAug 12, 2022
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

  • CVE-2022-30238HigJun 2, 2022
    risk 0.54cvss 8.3epss 0.01

    A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a session. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

  • CVE-2021-44458HigJan 10, 2022
    risk 0.54cvss 8.3epss 0.00

    Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would allow the attacker to execute arbitrary…

  • CVE-2021-32753HigJul 9, 2021
    risk 0.54cvss 8.3epss 0.01

    EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is configured for OAuth2 authentication and a…

  • CVE-2020-35785HigDec 30, 2020
    risk 0.54cvss 8.3epss 0.01

    NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365).

  • CVE-2020-26921HigOct 9, 2020
    risk 0.54cvss 8.3epss 0.01

    Certain NETGEAR devices are affected by authentication bypass. This affects GS110EMX before 1.0.1.7, GS810EMX before 1.7.1.3, XS512EM before 1.0.1.3, and XS724EM before 1.0.1.3.

  • CVE-2013-5582HigFeb 11, 2020
    risk 0.54cvss 7.8epss 0.04

    Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.

  • CVE-2014-8347HigFeb 11, 2020
    risk 0.54cvss 7.8epss 0.01

    An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.

  • CVE-2013-2569HigJan 29, 2020
    risk 0.54cvss 7.5epss 0.31

    A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.

  • CVE-2019-14909HigDec 4, 2019
    risk 0.54cvss 8.3epss 0.01

    A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.

  • CVE-2019-6832HigSep 17, 2019
    risk 0.54cvss 8.3epss 0.01

    A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known as homeLYnk), which could cause loss of control when an attacker bypasses the authentication.

  • CVE-2018-20735HigJan 17, 2019
    risk 0.54cvss 7.8epss 0.07

    An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was found that by default the PatrolCli / PATROL Agent…

  • CVE-2018-19458HigNov 22, 2018
    risk 0.54cvss 7.5epss 0.33

    In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.