CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,804)
page 92 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-52540 | Hig | 0.49 | 7.5 | 0.00 | Apr 8, 2024 | Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-25652 | Hig | 0.49 | 7.6 | 0.01 | Mar 14, 2024 | In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by… | ||
| CVE-2024-21427 | Hig | 0.49 | 7.5 | 0.02 | Mar 12, 2024 | Windows Kerberos Security Feature Bypass Vulnerability | ||
| CVE-2023-46717 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts. | ||
| CVE-2023-48703 | Hig | 0.49 | 7.5 | 0.01 | Mar 6, 2024 | RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` command line tool is called internally to verify the signature of SAML assertions. When `xmlsec1` is used… | ||
| CVE-2022-41738 | Hig | 0.49 | 7.5 | 0.00 | Feb 17, 2024 | IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812. | ||
| CVE-2023-50275 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2024 | HPE OneView may allow clusterService Authentication Bypass resulting in denial of service. | ||
| CVE-2023-52111 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2024-21632 | Hig | 0.49 | 8.6 | 0.01 | Jan 2, 2024 | omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth… | ||
| CVE-2023-6847 | Hig | 0.49 | 7.5 | 0.01 | Dec 21, 2023 | An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafted API request. To exploit this vulnerability, an attacker would need network access to the Enterprise Server appliance configured… | ||
| CVE-2023-51442 | Hig | 0.49 | 8.6 | 0.01 | Dec 21, 2023 | Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endpoint, allowing for authentication bypass. This exploit enables unauthorized access to any known account by utilizing a JSON Web… | ||
| CVE-2023-45801 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2023 | Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0. | ||
| CVE-2023-36004 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2023 | Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability | ||
| CVE-2023-5808 | Hig | 0.49 | 7.6 | 0.01 | Dec 5, 2023 | SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that… | ||
| CVE-2023-35137 | Hig | 0.49 | 7.5 | 0.01 | Nov 30, 2023 | An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain system information by sending a crafted URL to a vulnerable… | ||
| CVE-2023-39345 | Hig | 0.49 | 7.6 | 0.01 | Nov 6, 2023 | strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in… | ||
| CVE-2023-5627 | Hig | 0.49 | 7.5 | 0.00 | Nov 1, 2023 | A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web… | ||
| CVE-2023-44397 | Hig | 0.49 | 7.5 | 0.01 | Oct 30, 2023 | CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this… | ||
| CVE-2023-27377 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers. | ||
| CVE-2023-44096 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality. |
- risk 0.49cvss 7.5epss 0.00
Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.6epss 0.01
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by…
- risk 0.49cvss 7.5epss 0.02
Windows Kerberos Security Feature Bypass Vulnerability
- risk 0.49cvss 7.5epss 0.01
An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts.
- risk 0.49cvss 7.5epss 0.01
RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` command line tool is called internally to verify the signature of SAML assertions. When `xmlsec1` is used…
- risk 0.49cvss 7.5epss 0.00
IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.
- risk 0.49cvss 7.5epss 0.01
HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
- risk 0.49cvss 7.5epss 0.00
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
- risk 0.49cvss 8.6epss 0.01
omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth…
- risk 0.49cvss 7.5epss 0.01
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafted API request. To exploit this vulnerability, an attacker would need network access to the Enterprise Server appliance configured…
- risk 0.49cvss 8.6epss 0.01
Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endpoint, allowing for authentication bypass. This exploit enables unauthorized access to any known account by utilizing a JSON Web…
- risk 0.49cvss 7.5epss 0.01
Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.
- risk 0.49cvss 7.5epss 0.01
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.01
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that…
- risk 0.49cvss 7.5epss 0.01
An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain system information by sending a crafted URL to a vulnerable…
- risk 0.49cvss 7.6epss 0.01
strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in…
- risk 0.49cvss 7.5epss 0.00
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web…
- risk 0.49cvss 7.5epss 0.01
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this…
- risk 0.49cvss 7.5epss 0.01
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.