VYPR

CWE-288

Authentication Bypass Using an Alternate Path or Channel

BaseIncomplete

Description

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-127 · CAPEC-665

CVEs mapped to this weakness (639)

page 21 of 32
  • CVE-2024-35124HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.

  • CVE-2024-31916HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.

  • CVE-2023-50272HigDec 19, 2023
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass.

  • CVE-2023-39930HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.

  • CVE-2023-46319HigOct 23, 2023
    risk 0.49cvss 7.5epss 0.01

    WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface.

  • CVE-2022-42277HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can…

  • CVE-2022-42276HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can…

  • CVE-2022-23720HigJun 30, 2022
    risk 0.49cvss 7.5epss 0.00

    PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, such as those typically used by…

  • CVE-2021-31559HigMay 6, 2022
    risk 0.49cvss 7.5epss 0.01

    A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal…

  • CVE-2021-28131HigJul 22, 2021
    risk 0.49cvss 7.5epss 0.03

    Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially constructed…

  • CVE-2019-6551HigFeb 28, 2019
    risk 0.49cvss 7.5epss 0.03

    Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to cause a continual denial-of-service condition.

  • CVE-2018-5386HigJul 24, 2018
    risk 0.49cvss 7.5epss 0.05

    Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an information leak.

  • CVE-2026-22037HigJan 19, 2026
    risk 0.48cvss 8.4epss 0.00

    The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters (e.g., `/%61dmin` instead of…

  • CVE-2025-55012HigAug 11, 2025
    risk 0.48cvss epss 0.00

    Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission checks. An AI Agent could have exploited a permissions bypass vulnerability to create or modify a…

  • CVE-2025-47710HigMay 14, 2025
    risk 0.48cvss 7.4epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.

  • CVE-2024-47009HigOct 8, 2024
    risk 0.48cvss 7.3epss 0.02

    Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

  • CVE-2022-36093HigSep 8, 2022
    risk 0.48cvss 8.5epss 0.01

    XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart template, user accounts can be created even when user registration is disabled. This also circumvents any email verification.…

  • CVE-2021-27453HigDec 21, 2021
    risk 0.48cvss 7.3epss 0.01

    Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application, which may allow an attacker to gain access.

  • CVE-2026-42745HigMay 27, 2026
    risk 0.47cvss 7.3epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Authentication Bypass.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

  • CVE-2026-24206HigMay 20, 2026
    risk 0.47cvss 7.3epss 0.01

    NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.