VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 84 of 241
  • CVE-2023-47304HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.

  • CVE-2022-44569HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.01

    A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

  • CVE-2023-23632HigOct 12, 2023
    risk 0.51cvss 7.8epss 0.00

    BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first…

  • CVE-2022-33242HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.

  • CVE-2023-0905HigFeb 18, 2023
    risk 0.51cvss 7.3epss 0.03

    A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack…

  • CVE-2023-21817HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kerberos Elevation of Privilege Vulnerability

  • CVE-2022-30421HigJan 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.

  • CVE-2022-3156HigDec 27, 2022
    risk 0.51cvss 7.8epss 0.00

    A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve…

  • CVE-2022-37345HigNov 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-35094HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-36460HigApr 25, 2022
    risk 0.51cvss 7.8epss 0.00

    VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to…

  • CVE-2021-1950HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-4197HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for…

  • CVE-2022-24286HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In this case, the Named Pipe is also given Read and Write rights…

  • CVE-2022-24285HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority called ACCsvc through a named pipe. In this case, the Named Pipe is also given Read and Write rights to the general…

  • CVE-2021-40376HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.00

    otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.

  • CVE-2022-23729HigMar 4, 2022
    risk 0.51cvss 7.8epss 0.00

    When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.

  • CVE-2021-22796HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

  • CVE-2022-22990HigJan 13, 2022
    risk 0.51cvss 7.8epss 0.02

    A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP…

  • CVE-2021-35033HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable…