VYPR

CWE-305

Authentication Bypass by Primary Weakness

BaseDraft

Description

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (173)

page 6 of 9
  • CVE-2024-38433MedJul 11, 2024
    risk 0.44cvss 6.7epss 0.00

    Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to…

  • CVE-2023-28126MedMay 9, 2023
    risk 0.44cvss 5.9epss 0.67

    An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.

  • CVE-2025-7064MedJun 11, 2026
    risk 0.43cvss 6.6epss 0.00

    Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.

  • CVE-2025-68609MedJan 22, 2026
    risk 0.43cvss 6.6epss 0.00

    A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any…

  • CVE-2025-53534HigAug 5, 2025
    risk 0.43cvss —epss 0.01

    RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), they can execute system commands or take…

  • CVE-2026-8932HigJul 3, 2026
    risk 0.42cvss 7.5epss 0.00

    libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup.…

  • CVE-2026-40039MedApr 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to values to conduct phishing attacks and…

  • CVE-2026-1965MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.00

    libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a…

  • CVE-2025-59980MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. When the FTP server is enabled and a user named "ftp" or "anonymous" is…

  • CVE-2024-5956MedSep 5, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly

  • CVE-2023-4727HigJun 11, 2024
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to…

  • CVE-2022-40723MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.01

    The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.

  • CVE-2021-21403HigMar 26, 2021
    risk 0.42cvss 7.5epss 0.01

    In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21.

  • CVE-2026-53561HigAug 25, 2026
    risk 0.41cvss 7.4epss 0.00

    An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network attacker to…

  • CVE-2024-5957MedSep 5, 2024
    risk 0.41cvss 6.3epss 0.00

    This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

  • CVE-2024-34077HigMay 14, 2024
    risk 0.41cvss 7.3epss 0.01

    MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset another user's password and takeover their account, if the victim has an incomplete request pending. The exploit…

  • CVE-2024-3847MedApr 17, 2024
    risk 0.40cvss 6.1epss 0.01

    Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2022-4722HigDec 27, 2022
    risk 0.40cvss 7.2epss 0.01

    Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-38081MedSep 9, 2022
    risk 0.40cvss 6.2epss 0.00

    OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.

  • CVE-2022-38064MedSep 9, 2022
    risk 0.40cvss 6.2epss 0.00

    OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.