VYPR

CWE-305

Authentication Bypass by Primary Weakness

BaseDraft

Description

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (159)

page 4 of 8
  • CVE-2021-3850CriJan 25, 2022
    risk 0.52cvss 9.1epss 0.02

    Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.

  • CVE-2024-10394HigNov 14, 2024
    risk 0.51cvss 7.8epss 0.00

    A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credentials in that PAG.

  • CVE-2024-20015HigFeb 5, 2024
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441419; Issue ID: ALPS08441419.

  • CVE-2022-23729HigMar 4, 2022
    risk 0.51cvss 7.8epss 0.00

    When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.

  • CVE-2026-41052HigJun 29, 2026
    risk 0.50cvss 8.8epss 0.00

    Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.

  • CVE-2026-2652HigMay 15, 2026
    risk 0.50cvss 8.6epss 0.19

    A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces…

  • CVE-2024-10082HigNov 6, 2024
    risk 0.50cvss 8.7epss 0.00

    CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root user up until 6.24.1 is generated in a…

  • CVE-2023-6998HigDec 30, 2023
    risk 0.50cvss 7.7epss 0.00

    Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0.

  • CVE-2021-45031HigMar 30, 2022
    risk 0.50cvss 7.7epss 0.01

    A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate high privileged accounts passwords.

  • CVE-2026-9047HigMay 22, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue…

  • CVE-2025-51663HigNov 19, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protection and failed attempt restrictions by faking X-Real-IP and X-Forwarded-For HTTP headers. This can enable attackers to perform DoS attacks or…

  • CVE-2024-20378HigMay 1, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. This vulnerability is due to a lack of authentication for specific endpoints of the…

  • CVE-2023-2959HigJul 17, 2023
    risk 0.49cvss 7.5epss 0.01

    Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.

  • CVE-2021-43175HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOautodial validate the username and password…

  • CVE-2020-15078HigApr 26, 2021
    risk 0.49cvss 7.5epss 0.05

    OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

  • CVE-2020-10126HigAug 21, 2020
    risk 0.49cvss 7.6epss 0.00

    NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restart the host computer and execute arbitrary code with SYSTEM privileges because…

  • CVE-2025-56132HigSep 30, 2025
    risk 0.48cvss 7.3epss 0.01

    LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence of user accounts.…

  • CVE-2021-28503HigFeb 4, 2022
    risk 0.48cvss 7.4epss 0.01

    The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

  • CVE-2021-3547HigJul 12, 2021
    risk 0.48cvss 7.4epss 0.01

    OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

  • CVE-2020-14359HigFeb 23, 2021
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jetty). This means there is no protection when we put a…