CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,804)
page 95 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39254 | Hig | 0.49 | 8.6 | 0.01 | Sep 29, 2022 | matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without… | ||
| CVE-2022-39252 | Hig | 0.49 | 8.6 | 0.01 | Sep 29, 2022 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives… | ||
| CVE-2022-39250 | Hig | 0.49 | 8.6 | 0.01 | Sep 29, 2022 | Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user… | ||
| CVE-2022-39251 | Hig | 0.49 | 8.6 | 0.01 | Sep 28, 2022 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield.… | ||
| CVE-2022-39248 | Hig | 0.49 | 8.6 | 0.01 | Sep 28, 2022 | matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a… | ||
| CVE-2022-22523 | Hig | 0.49 | 7.5 | 0.01 | Sep 28, 2022 | An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled. | ||
| CVE-2022-3119 | Hig | 0.49 | 7.5 | 0.00 | Sep 26, 2022 | The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated… | ||
| CVE-2022-39801 | Hig | 0.49 | 7.5 | 0.01 | Sep 13, 2022 | SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to… | ||
| CVE-2022-35198 | Hig | 0.49 | 7.5 | 0.01 | Aug 18, 2022 | Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information. | ||
| CVE-2022-36524 | Hig | 0.49 | 7.5 | 0.01 | Aug 15, 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh. | ||
| CVE-2016-0796 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide… | ||
| CVE-2022-31164 | Hig | 0.49 | 7.5 | 0.01 | Jul 22, 2022 | Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been patched in version 0.7.51. | ||
| CVE-2022-34535 | Hig | 0.49 | 7.5 | 0.01 | Jul 19, 2022 | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files. | ||
| CVE-2022-33736 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2022 | A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (All versions < V13.2.20220624). The affected applications do not properly validate login information during authentication. This could lead to denial of service… | ||
| CVE-2021-41638 | Hig | 0.49 | 7.5 | 0.02 | Jun 24, 2022 | The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username. | ||
| CVE-2022-1801 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2022 | The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for… | ||
| CVE-2022-31083 | Hig | 0.49 | 8.6 | 0.01 | Jun 17, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be… | ||
| CVE-2022-32276 | Hig | 0.49 | 7.5 | 0.04 | Jun 17, 2022 | Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability | ||
| CVE-2018-18907 | Hig | 0.49 | 7.5 | 0.01 | Jun 16, 2022 | An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data Frames to the AP without encryption. | ||
| CVE-2022-29865 | Hig | 0.49 | 7.5 | 0.02 | Jun 16, 2022 | OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials. |
- risk 0.49cvss 8.6epss 0.01
matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without…
- risk 0.49cvss 8.6epss 0.01
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives…
- risk 0.49cvss 8.6epss 0.01
Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user…
- risk 0.49cvss 8.6epss 0.01
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield.…
- risk 0.49cvss 8.6epss 0.01
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a…
- risk 0.49cvss 7.5epss 0.01
An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.
- risk 0.49cvss 7.5epss 0.00
The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated…
- risk 0.49cvss 7.5epss 0.01
SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to…
- risk 0.49cvss 7.5epss 0.01
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
- risk 0.49cvss 7.5epss 0.01
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
- risk 0.49cvss 7.5epss 0.01
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide…
- risk 0.49cvss 7.5epss 0.01
Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been patched in version 0.7.51.
- risk 0.49cvss 7.5epss 0.01
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (All versions < V13.2.20220624). The affected applications do not properly validate login information during authentication. This could lead to denial of service…
- risk 0.49cvss 7.5epss 0.02
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.
- risk 0.49cvss 7.5epss 0.01
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for…
- risk 0.49cvss 8.6epss 0.01
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be…
- risk 0.49cvss 7.5epss 0.04
Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data Frames to the AP without encryption.
- risk 0.49cvss 7.5epss 0.02
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.