VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 90 of 253
  • CVE-2020-10594CriMar 15, 2020
    risk 0.52cvss 9.1epss 0.02

    An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE:…

  • CVE-2019-17134CriOct 8, 2019
    risk 0.52cvss 9.1epss 0.02

    Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the…

  • CVE-2018-7358MedNov 14, 2018
    risk 0.52cvss 6.5epss 0.88

    ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.

  • CVE-2018-1112HigApr 25, 2018
    risk 0.52cvss 8.0epss 0.03

    glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

  • CVE-2017-7314HigJun 7, 2017
    risk 0.52cvss 7.5epss 0.02

    An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available.

  • CVE-2017-8827CriMay 8, 2017
    risk 0.52cvss 9.1epss 0.02

    forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.

  • CVE-2017-8223HigApr 25, 2017
    risk 0.52cvss 7.5epss 0.03

    On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0.

  • CVE-2017-6104HigMar 2, 2017
    risk 0.52cvss 7.5epss 0.06

    Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

  • CVE-2026-20891HigAug 11, 2026
    risk 0.51cvss 7.9epss 0.00

    Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code…

  • CVE-2026-12112HigJun 23, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without…

  • CVE-2026-26141HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26128HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.01

    Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24294HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.05

    Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-0405HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

  • CVE-2025-43281HigOct 15, 2025
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.

  • CVE-2025-10672HigSep 18, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIBatteryHelper/XPC/BatteryXPCService.swift of the component com.collweb.AIBatteryHelper. The manipulation results in missing authentication. The attack requires…

  • CVE-2025-9815HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.00

    A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the…

  • CVE-2025-41459HigJul 21, 2025
    risk 0.51cvss 7.8epss 0.00

    Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.

  • CVE-2024-13088HigJun 6, 2025
    risk 0.51cvss 7.8epss 0.00

    An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QuRouter…

  • CVE-2025-0217HigMay 5, 2025
    risk 0.51cvss 7.8epss 0.00

    BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to…