VYPR

CWE-592

DEPRECATED: Authentication Bypass Issues

ClassDeprecated

Description

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

CVEs mapped to this weakness (24)

page 1 of 2
  • CVE-2019-14910CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

  • CVE-2019-3899CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.01

    It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.

  • CVE-2014-5432CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.03

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A remote attacker may be able to make unauthorized configuration changes to the WBM, as well as issue…

  • CVE-2018-10933CriOct 17, 2018
    risk 0.62cvss 9.1epss 0.92

    A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

  • CVE-2018-1085CriJun 15, 2018
    risk 0.59cvss 9.0epss 0.02

    openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the values of ETCD_CLIENT_CERT_AUTH and ETCD_PEER_CLIENT_CERT_AUTH in etcd.conf result in etcd being…

  • CVE-2017-2684CriFeb 22, 2017
    risk 0.59cvss 9.0epss 0.02

    Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.

  • CVE-2026-43512CriMay 12, 2026
    risk 0.57cvss 9.8epss 0.01

    DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.…

  • CVE-2019-14843HigJan 7, 2020
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped…

  • CVE-2017-2650HigJul 27, 2018
    risk 0.55cvss 8.5epss 0.01

    It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins.

  • CVE-2019-14909HigDec 4, 2019
    risk 0.54cvss 8.3epss 0.01

    A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.

  • CVE-2019-10201HigAug 14, 2019
    risk 0.53cvss 8.1epss 0.01

    It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the sections, the message is still accepted, and the message can be modified. An attacker could use this…

  • CVE-2024-38884HigAug 2, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms

  • CVE-2016-8371HigApr 5, 2018
    risk 0.51cvss 7.3epss 0.11

    The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

  • CVE-2023-30971MedDec 19, 2025
    risk 0.44cvss 6.8epss 0.00

    Gotham Gaia application was found to be exposing multiple unauthenticated endpoints.

  • CVE-2019-10198MedJul 31, 2019
    risk 0.42cvss 6.5epss 0.02

    An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through…

  • CVE-2024-42759MedSep 9, 2024
    risk 0.41cvss 6.3epss 0.00

    An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

  • CVE-2017-7536HigJan 10, 2018
    risk 0.39cvss 7.0epss 0.00

    In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By…

  • CVE-2018-10847MedJul 30, 2018
    risk 0.27cvss 4.2epss 0.02

    prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session…

  • CVE-2017-12164MedJul 26, 2018
    risk 0.27cvss 4.1epss 0.00

    A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

  • CVE-2016-8616LowAug 1, 2018
    risk 0.17cvss 3.7epss 0.03

    A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has…