VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 86 of 241
  • CVE-2019-6854HigJan 6, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must…

  • CVE-2019-8533HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.00

    A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave 10.14.4. A Mac may not lock when disconnecting from an external monitor.

  • CVE-2014-1867HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.00

    suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution

  • CVE-2019-17437HigDec 5, 2019
    risk 0.51cvss 7.8epss 0.00

    An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 versions prior to 8.0.20; 8.1 versions…

  • CVE-2019-19519HigDec 5, 2019
    risk 0.51cvss 7.8epss 0.00

    In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.

  • CVE-2019-11170HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    Authentication bypass in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via local access.

  • CVE-2019-5223HigAug 13, 2019
    risk 0.51cvss 7.8epss 0.01

    PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mode data properly, successful exploit could result in malicious code execution.

  • CVE-2019-5679HigAug 6, 2019
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authenticated, which may lead to code execution, denial of service, escalation of privileges, and information disclosure, code…

  • CVE-2018-1987HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed in plain text in the ERP trace file. IBM X-Force ID: 154280.

  • CVE-2018-13927HigJul 22, 2019
    risk 0.51cvss 7.8epss 0.00

    Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…

  • CVE-2018-19999HigJun 7, 2019
    risk 0.51cvss 7.8epss 0.01

    The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit…

  • CVE-2018-12013HigMay 24, 2019
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2018-18256HigMar 15, 2019
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher.

  • CVE-2018-18255HigMar 15, 2019
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in CapMon Access Manager 5.4.1.1005. The client applications of AccessManagerCoreService.exe communicate with this server through named pipes. A user can initiate communication with the server by creating a named pipe and sending commands to achieve…

  • CVE-2019-1664HigFeb 21, 2019
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by…

  • CVE-2018-16160HigNov 15, 2018
    risk 0.51cvss 7.8epss 0.00

    SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Windows PC.

  • CVE-2018-6689HigOct 3, 2018
    risk 0.51cvss 7.8epss 0.00

    Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.

  • CVE-2018-6617HigMay 11, 2018
    risk 0.51cvss 7.8epss 0.00

    Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password.

  • CVE-2018-9232HigMay 1, 2018
    risk 0.51cvss 7.8epss 0.01

    Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and use it as an update.

  • CVE-2016-8380HigApr 5, 2018
    risk 0.51cvss 7.3epss 0.11

    The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.