VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 92 of 241
  • CVE-2023-52540HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-25652HigMar 14, 2024
    risk 0.49cvss 7.6epss 0.01

    In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by…

  • CVE-2024-21427HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Kerberos Security Feature Bypass Vulnerability

  • CVE-2023-46717HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts.

  • CVE-2023-48703HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.01

    RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` command line tool is called internally to verify the signature of SAML assertions. When `xmlsec1` is used…

  • CVE-2022-41738HigFeb 17, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.

  • CVE-2023-50275HigJan 23, 2024
    risk 0.49cvss 7.5epss 0.01

    HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

  • CVE-2023-52111HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2024-21632HigJan 2, 2024
    risk 0.49cvss 8.6epss 0.01

    omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth…

  • CVE-2023-6847HigDec 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafted API request. To exploit this vulnerability, an attacker would need network access to the Enterprise Server appliance configured…

  • CVE-2023-51442HigDec 21, 2023
    risk 0.49cvss 8.6epss 0.01

    Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endpoint, allowing for authentication bypass. This exploit enables unauthorized access to any known account by utilizing a JSON Web…

  • CVE-2023-45801HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.

  • CVE-2023-36004HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability

  • CVE-2023-5808HigDec 5, 2023
    risk 0.49cvss 7.6epss 0.01

    SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that…

  • CVE-2023-35137HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain system information by sending a crafted URL to a vulnerable…

  • CVE-2023-39345HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in…

  • CVE-2023-5627HigNov 1, 2023
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web…

  • CVE-2023-44397HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.01

    CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this…

  • CVE-2023-27377HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.

  • CVE-2023-44096HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.