VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 74 of 241
  • CVE-2024-10114HigNov 5, 2024
    risk 0.53cvss 8.1epss 0.01

    The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated…

  • CVE-2024-10327HigOct 24, 2024
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the…

  • CVE-2024-9947HigOct 23, 2024
    risk 0.53cvss 8.1epss 0.01

    The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to…

  • CVE-2024-45051HigOct 7, 2024
    risk 0.53cvss 8.2epss 0.00

    Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in the latest stable, beta and…

  • CVE-2024-47807HigOct 2, 2024
    risk 0.53cvss 8.1epss 0.01

    Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.

  • CVE-2024-47806HigOct 2, 2024
    risk 0.53cvss 8.1epss 0.01

    Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.

  • CVE-2024-47125HigSep 26, 2024
    risk 0.53cvss 8.1epss 0.00

    The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to the current release for enhanced encryption protocols.

  • CVE-2024-47078HigSep 25, 2024
    risk 0.53cvss 8.1epss 0.00

    Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied through a connected phone (i.e., via…

  • CVE-2024-45823HigSep 12, 2024
    risk 0.53cvss 8.1epss 0.01

    CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information…

  • CVE-2024-36444HigAug 22, 2024
    risk 0.53cvss 8.1epss 0.01

    cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

  • CVE-2024-42336HigAug 20, 2024
    risk 0.53cvss 8.2epss 0.00

    Servision - CWE-287: Improper Authentication

  • CVE-2024-24554HigJun 24, 2024
    risk 0.53cvss 8.2epss 0.00

    Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This allows attackers to authenticate against the Bludit API.

  • CVE-2024-26331HigApr 30, 2024
    risk 0.53cvss 7.5epss 0.51

    ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser.…

  • CVE-2023-51471HigApr 24, 2024
    risk 0.53cvss 8.2epss 0.01

    Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.

  • CVE-2023-51405HigApr 24, 2024
    risk 0.53cvss 8.2epss 0.01

    Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.

  • CVE-2024-28735HigMar 20, 2024
    risk 0.53cvss 8.1epss 0.01

    Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.

  • CVE-2023-36648HigDec 12, 2023
    risk 0.53cvss 8.2epss 0.01

    Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Apache Kafka (as consumer and producer).

  • CVE-2023-44302HigDec 4, 2023
    risk 0.53cvss 8.1epss 0.01

    Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access of resources or functionality that could possibly lead to execute arbitrary code.

  • CVE-2023-46290HigOct 27, 2023
    risk 0.53cvss 8.1epss 0.03

    Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can…

  • CVE-2023-37283HigOct 25, 2023
    risk 0.53cvss 8.1epss 0.01

    Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter