VYPR

CWE-303

Incorrect Implementation of Authentication Algorithm

BaseDraft

Description

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

This incorrect implementation may allow authentication to be bypassed.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-90

CVEs mapped to this weakness (109)

page 6 of 6
  • CVE-2024-36250LowNov 9, 2024
    risk 0.20cvss 3.1epss 0.00

    Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds

  • CVE-2024-10214LowOct 28, 2024
    risk 0.16cvss 3.5epss 0.00

    Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.

  • CVE-2026-66028MedJul 27, 2026
    risk 0.00cvss 6.7epss 0.00

    Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field…

  • CVE-2026-57852MedJul 20, 2026
    risk 0.00cvss 5.6epss 0.01

    Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single…

  • CVE-2026-50360HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-35190MedMay 17, 2024
    risk 0.00cvss 5.8epss 0.01

    Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

  • CVE-2023-39953MedAug 10, 2023
    risk 0.00cvss 4.8epss 0.01

    user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, missing verification of the issuer would have allowed an attacker to perform a man-in-the-middle attack returning corrupted or…

  • CVE-2022-41985HigMay 10, 2023
    risk 0.00cvss 8.6epss 0.01

    An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can send a sequence of unauthenticated packets…

  • CVE-2021-21378HigMar 11, 2021
    risk 0.00cvss 8.2epss 0.02

    Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authentication by presenting a JWT token with an issuer that is not in the provider list when Envoy's JWT Authentication filter is configured with the…