VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 83 of 241
  • CVE-2017-8827CriMay 8, 2017
    risk 0.52cvss 9.1epss 0.02

    forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.

  • CVE-2017-8223HigApr 25, 2017
    risk 0.52cvss 7.5epss 0.04

    On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0.

  • CVE-2017-6104HigMar 2, 2017
    risk 0.52cvss 7.5epss 0.07

    Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

  • CVE-2026-12112HigJun 23, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without…

  • CVE-2026-26141HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26128HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.01

    Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24294HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.05

    Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-0405HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

  • CVE-2025-43281HigOct 15, 2025
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.

  • CVE-2025-10672HigSep 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIBatteryHelper/XPC/BatteryXPCService.swift of the component com.collweb.AIBatteryHelper. The manipulation results in missing authentication. The attack requires…

  • CVE-2025-9815HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.00

    A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the…

  • CVE-2025-41459HigJul 21, 2025
    risk 0.51cvss 7.8epss 0.00

    Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.

  • CVE-2024-13088HigJun 6, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter…

  • CVE-2025-0217HigMay 5, 2025
    risk 0.51cvss 7.8epss 0.00

    BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to…

  • CVE-2024-56329HigDec 20, 2024
    risk 0.51cvss epss 0.01

    Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jetstream, with scaffolding that has support for Laravel Socialite. When linking a social account to an already authenticated user,…

  • CVE-2024-49076HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

  • CVE-2024-40713HigSep 7, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.

  • CVE-2019-6198HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

  • CVE-2019-6197HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

  • CVE-2023-48257HigJan 10, 2024
    risk 0.51cvss 7.8epss 0.01

    The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or…