CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,804)
page 93 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0813 | Hig | 0.49 | 7.5 | 0.01 | Sep 15, 2023 | A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows… | ||
| CVE-2022-47848 | Hig | 0.49 | 7.5 | 0.01 | Sep 15, 2023 | An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml page of the UPnP service. | ||
| CVE-2023-39981 | Hig | 0.49 | 7.5 | 0.01 | Sep 2, 2023 | A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker. | ||
| CVE-2023-25913 | Hig | 0.49 | 7.5 | 0.01 | Aug 21, 2023 | Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information. | ||
| CVE-2023-39415 | Hig | 0.49 | 7.5 | 0.01 | Aug 18, 2023 | Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel… | ||
| CVE-2023-3263 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid… | ||
| CVE-2023-39380 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally. | ||
| CVE-2023-33363 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2023 | An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers. | ||
| CVE-2023-2626 | Hig | 0.49 | 7.5 | 0.00 | Jul 25, 2023 | There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks,… | ||
| CVE-2023-2959 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2023 | Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2. | ||
| CVE-2023-3127 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2023 | An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights. | ||
| CVE-2023-35940 | Hig | 0.49 | 7.5 | 0.01 | Jul 5, 2023 | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue. | ||
| CVE-2022-48496 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2023 | Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized. | ||
| CVE-2022-48494 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2023 | Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized. | ||
| CVE-2023-30223 | Hig | 0.49 | 7.5 | 0.01 | Jun 16, 2023 | A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions. | ||
| CVE-2022-40536 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2023-30063 | Hig | 0.49 | 7.5 | 0.01 | May 1, 2023 | D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass. | ||
| CVE-2023-30061 | Hig | 0.49 | 7.5 | 0.01 | May 1, 2023 | D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi. | ||
| CVE-2022-45456 | Hig | 0.49 | 7.5 | 0.00 | Apr 26, 2023 | Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161. |
- risk 0.49cvss 7.5epss 0.01
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml page of the UPnP service.
- risk 0.49cvss 7.5epss 0.01
A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker.
- risk 0.49cvss 7.5epss 0.01
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.
- risk 0.49cvss 7.5epss 0.01
Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel…
- risk 0.49cvss 7.5epss 0.01
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid…
- risk 0.49cvss 7.5epss 0.00
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.
- risk 0.49cvss 7.5epss 0.01
An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers.
- risk 0.49cvss 7.5epss 0.00
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks,…
- risk 0.49cvss 7.5epss 0.01
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
- risk 0.49cvss 7.5epss 0.01
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
- risk 0.49cvss 7.5epss 0.01
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
- risk 0.49cvss 7.5epss 0.00
Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161.