CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,056)
page 91 of 253| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-56329 | Hig | 0.51 | — | 0.01 | Dec 20, 2024 | Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jetstream, with scaffolding that has support for Laravel Socialite. When linking a social account to an already authenticated user,… | ||
| CVE-2024-49076 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | ||
| CVE-2024-40713 | Hig | 0.51 | 7.8 | 0.00 | Sep 7, 2024 | A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA. | ||
| CVE-2019-6198 | Hig | 0.51 | 7.8 | 0.00 | Jul 31, 2024 | A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges. | ||
| CVE-2019-6197 | Hig | 0.51 | 7.8 | 0.00 | Jul 31, 2024 | A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges. | ||
| CVE-2023-48257 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2024 | The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or… | ||
| CVE-2023-47304 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device. | ||
| CVE-2022-44569 | Hig | 0.51 | 7.8 | 0.01 | Nov 3, 2023 | A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication. | ||
| CVE-2023-23632 | Hig | 0.51 | 7.8 | 0.00 | Oct 12, 2023 | BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first… | ||
| CVE-2022-33242 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD. | ||
| CVE-2023-0905 | Hig | 0.51 | 7.3 | 0.03 | Feb 18, 2023 | A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack… | ||
| CVE-2023-21817 | Hig | 0.51 | 7.8 | 0.01 | Feb 14, 2023 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2022-30421 | Hig | 0.51 | 7.8 | 0.00 | Jan 31, 2023 | Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module. | ||
| CVE-2022-3156 | Hig | 0.51 | 7.8 | 0.00 | Dec 27, 2022 | A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve… | ||
| CVE-2022-37345 | Hig | 0.51 | 7.8 | 0.00 | Nov 11, 2022 | Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2021-35094 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-36460 | Hig | 0.51 | 7.8 | 0.00 | Apr 25, 2022 | VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to… | ||
| CVE-2021-1950 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2022 | Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2021-4197 | Hig | 0.51 | 7.8 | 0.01 | Mar 23, 2022 | An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for… | ||
| CVE-2022-24286 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2022 | Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In this case, the Named Pipe is also given Read and Write rights… |
- risk 0.51cvss —epss 0.01
Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jetstream, with scaffolding that has support for Laravel Socialite. When linking a social account to an already authenticated user,…
- risk 0.51cvss 7.8epss 0.01
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
- risk 0.51cvss 7.8epss 0.00
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.
- risk 0.51cvss 7.8epss 0.00
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.
- risk 0.51cvss 7.8epss 0.01
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or…
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.
- risk 0.51cvss 7.8epss 0.01
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
- risk 0.51cvss 7.8epss 0.00
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first…
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
- risk 0.51cvss 7.3epss 0.03
A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack…
- risk 0.51cvss 7.8epss 0.01
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.
- risk 0.51cvss 7.8epss 0.00
A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve…
- risk 0.51cvss 7.8epss 0.00
Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to…
- risk 0.51cvss 7.8epss 0.00
Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
- risk 0.51cvss 7.8epss 0.01
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for…
- risk 0.51cvss 7.8epss 0.00
Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In this case, the Named Pipe is also given Read and Write rights…