VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 93 of 241
  • CVE-2023-0813HigSep 15, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows…

  • CVE-2022-47848HigSep 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml page of the UPnP service.

  • CVE-2023-39981HigSep 2, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker.

  • CVE-2023-25913HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.

  • CVE-2023-39415HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel…

  • CVE-2023-3263HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid…

  • CVE-2023-39380HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

  • CVE-2023-33363HigAug 3, 2023
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers.

  • CVE-2023-2626HigJul 25, 2023
    risk 0.49cvss 7.5epss 0.00

    There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks,…

  • CVE-2023-2959HigJul 17, 2023
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.

  • CVE-2023-3127HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

  • CVE-2023-35940HigJul 5, 2023
    risk 0.49cvss 7.5epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.

  • CVE-2022-48496HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.

  • CVE-2022-48494HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.

  • CVE-2023-30223HigJun 16, 2023
    risk 0.49cvss 7.5epss 0.01

    A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.

  • CVE-2022-40536HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.

  • CVE-2022-40521HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to improper authorization in Modem

  • CVE-2023-30063HigMay 1, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.

  • CVE-2023-30061HigMay 1, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.

  • CVE-2022-45456HigApr 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161.