VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 94 of 241
  • CVE-2023-21027HigMar 24, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-25264HigFeb 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.

  • CVE-2022-47508HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.

  • CVE-2022-48294HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2020-20402HigJan 31, 2023
    risk 0.49cvss 7.5epss 0.01

    Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.

  • CVE-2022-4441HigJan 31, 2023
    risk 0.49cvss 7.6epss 0.01

    Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 04.9.1.

  • CVE-2023-24830HigJan 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.

  • CVE-2021-43444HigJan 23, 2023
    risk 0.49cvss 7.5epss 0.01

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.

  • CVE-2023-21841HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP…

  • CVE-2022-25027HigJan 12, 2023
    risk 0.49cvss 7.5epss 0.01

    The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

  • CVE-2022-47976HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.

  • CVE-2022-46170HigDec 22, 2022
    risk 0.49cvss 8.6epss 0.01

    CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one…

  • CVE-2021-35252HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

  • CVE-2022-25685HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-40242HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    MegaRAC Default Credentials Vulnerability

  • CVE-2022-20918HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS)…

  • CVE-2022-25667HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking

  • CVE-2022-36370HigNov 11, 2022
    risk 0.49cvss 7.5epss 0.00

    Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-38744HigOct 27, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages…

  • CVE-2022-23769HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution.