VYPR

CWE-592

DEPRECATED: Authentication Bypass Issues

ClassDeprecated

Description

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

CVEs mapped to this weakness (24)

page 2 of 2
  • CVE-2018-14643CriSep 21, 2018
    risk 0.00cvss 9.8epss 0.06

    An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.

  • CVE-2017-7537MedJul 26, 2018
    risk 0.00cvss 5.9epss 0.01

    It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing…

  • CVE-2014-2367Jul 19, 2014
    risk 0.00cvss epss 0.02

    The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.

  • CVE-2012-4688Dec 31, 2012
    risk 0.00cvss epss 0.02

    The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.