VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 98 of 241
  • CVE-2020-26557HigMay 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each…

  • CVE-2002-2438HigMay 18, 2021
    risk 0.49cvss 7.5epss 0.04

    TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.

  • CVE-2021-29047HigMay 16, 2021
    risk 0.49cvss 7.5epss 0.01

    The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA…

  • CVE-2021-20092HigApr 29, 2021
    risk 0.49cvss 7.5epss 0.08

    The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.

  • CVE-2021-20590HigApr 22, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server versions 01.39.010 and prior, GOT2000 series GT21 model GT2107-WTBD VNC server versions 01.40.000 and prior, GOT2000 series GT21 model…

  • CVE-2020-28973HigApr 21, 2021
    risk 0.49cvss 7.5epss 0.01

    The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system, such as usernames and passwords. This information can…

  • CVE-2020-7856HigApr 20, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient authentication validation.

  • CVE-2021-27990HigApr 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.

  • CVE-2019-20464HigApr 2, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over UDP. However, the device offers many more services that also enable streaming. Although the service used by the mobile application…

  • CVE-2021-22496HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.

  • CVE-2020-23355HigJan 27, 2021
    risk 0.49cvss 7.5epss 0.01

    ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234…

  • CVE-2020-28874HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.02

    reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

  • CVE-2020-24641HigJan 15, 2021
    risk 0.49cvss 7.5epss 0.01

    In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately…

  • CVE-2020-5686HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.01

    Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific…

  • CVE-2020-36176HigJan 6, 2021
    risk 0.49cvss 7.5epss 0.01

    The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

  • CVE-2020-27254HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to…

  • CVE-2020-27199HigDec 17, 2020
    risk 0.49cvss 7.5epss 0.03

    The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token…

  • CVE-2020-0460HigDec 14, 2020
    risk 0.49cvss 7.5epss 0.01

    In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-27408HigDec 4, 2020
    risk 0.49cvss 7.5epss 0.02

    OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.

  • CVE-2020-8272HigNov 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8