VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 76 of 241
  • CVE-2022-40616HigSep 21, 2022
    risk 0.53cvss 8.1epss 0.01

    IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tasks they should not have access to. IBM X-Force ID: 236311.

  • CVE-2022-33202HigJun 27, 2022
    risk 0.53cvss 8.1epss 0.00

    Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by…

  • CVE-2022-31463HigJun 2, 2022
    risk 0.53cvss 8.2epss 0.01

    Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used.

  • CVE-2021-26253HigMay 6, 2022
    risk 0.53cvss 8.1epss 0.01

    A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and does not impact or…

  • CVE-2022-1065HigApr 19, 2022
    risk 0.53cvss 8.1epss 0.03

    A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions prior to R4 of 2022-01-15; v2020 versions prior to R6 of…

  • CVE-2022-28376HigApr 3, 2022
    risk 0.53cvss 8.1epss 0.01

    Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, e.g., at the 10.0.0.1 IP address. The password (for the verizon username) is calculated by concatenating the serial number and the model…

  • CVE-2022-25155HigApr 1, 2022
    risk 0.53cvss 8.1epss 0.02

    Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions,…

  • CVE-2021-44759HigMar 23, 2022
    risk 0.53cvss 8.1epss 0.02

    Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.

  • CVE-2021-21902HigDec 22, 2021
    risk 0.53cvss 8.1epss 0.02

    An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can lead to authentication bypass via session hijacking. An attacker can send a sequence of requests…

  • CVE-2021-43833HigDec 16, 2021
    risk 0.53cvss 8.1epss 0.01

    eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address. This vulnerability impacts all instances…

  • CVE-2021-43935HigDec 15, 2021
    risk 0.53cvss 8.1epss 0.01

    The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password,…

  • CVE-2021-36306HigNov 20, 2021
    risk 0.53cvss 8.1epss 0.04

    Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to gain access and perform actions on the affected system.

  • CVE-2021-24647HigNov 8, 2021
    risk 0.53cvss 8.1epss 0.10

    The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing…

  • CVE-2021-38161HigNov 3, 2021
    risk 0.53cvss 8.1epss 0.02

    Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.

  • CVE-2021-33895HigJun 25, 2021
    risk 0.53cvss 8.1epss 0.01

    ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verifying the Password returns 0 (no error). The reason is that…

  • CVE-2021-31520HigMay 10, 2021
    risk 0.53cvss 8.1epss 0.04

    A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently logged-in administrators' session session token in order to gain access to the product's web management interface.

  • CVE-2021-25147HigApr 28, 2021
    risk 0.53cvss 8.1epss 0.01

    A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-23923HigApr 1, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.

  • CVE-2020-5148HigMar 5, 2021
    risk 0.53cvss 8.2epss 0.01

    SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker…

  • CVE-2020-2050HigNov 12, 2020
    risk 0.53cvss 8.2epss 0.01

    An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and…