VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,056)

page 92 of 253
  • CVE-2022-24285HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority called ACCsvc through a named pipe. In this case, the Named Pipe is also given Read and Write rights to the general…

  • CVE-2021-40376HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.00

    otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.

  • CVE-2022-23729HigMar 4, 2022
    risk 0.51cvss 7.8epss 0.00

    When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.

  • CVE-2021-22796HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

  • CVE-2022-22990HigJan 13, 2022
    risk 0.51cvss 7.8epss 0.02

    A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP…

  • CVE-2021-35033HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable…

  • CVE-2021-0096HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN, NUC7i7DN before version 1.78.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0595HigOct 6, 2021
    risk 0.51cvss 7.8epss 0.00

    In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-41286HigOct 5, 2021
    risk 0.51cvss 7.8epss 0.00

    Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the application, the validity of the password is checked locally. All communication to the database backend is made via the same technical account. Consequently, an…

  • CVE-2021-33700HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.00

    SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take…

  • CVE-2021-30605HigSep 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.

  • CVE-2021-27794HigAug 12, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.

  • CVE-2021-32579HigAug 5, 2021
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service API.

  • CVE-2020-4983HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands. IBM X-Force ID: 192586.

  • CVE-2020-9207HigDec 29, 2020
    risk 0.51cvss 7.8epss 0.01

    There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to bypass current verification mechanism. This can compromise…

  • CVE-2020-5425HigOct 31, 2020
    risk 0.51cvss 7.9epss 0.01

    Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same username, from two…

  • CVE-2020-24848HigOct 23, 2020
    risk 0.51cvss 7.8epss 0.00

    FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent access to the local system.

  • CVE-2020-24563HigSep 29, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to…

  • CVE-2019-10562HigSep 8, 2020
    risk 0.51cvss 7.8epss 0.00

    u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer…

  • CVE-2020-15482HigAug 26, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.