VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 97 of 241
  • CVE-2021-37100HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.

  • CVE-2021-37043HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious application processes occupy system resources.

  • CVE-2021-43203HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.

  • CVE-2021-41312HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the…

  • CVE-2021-22473HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-37624HigOct 25, 2021
    risk 0.49cvss 7.5epss 0.04

    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam…

  • CVE-2021-30312HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30302HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2021-37414HigSep 10, 2021
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.

  • CVE-2020-13929HigSep 2, 2021
    risk 0.49cvss 7.5epss 0.03

    Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

  • CVE-2021-36370HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.

  • CVE-2021-22025HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster.

  • CVE-2021-37172HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to…

  • CVE-2021-37545HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.

  • CVE-2020-16839HigJul 30, 2021
    risk 0.49cvss 7.5epss 0.01

    On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.

  • CVE-2021-34676HigJul 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.

  • CVE-2021-34675HigJul 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.

  • CVE-2021-25442HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.

  • CVE-2020-22176HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.

  • CVE-2020-14380HigJun 2, 2021
    risk 0.49cvss 7.5epss 0.01

    An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.