CWE-1390

Weak Authentication

Parent: CWE-287 - Improper Authentication

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

86 vulnerabilities with CWE-1390
CVE-2024-36787 HIGH
Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 - Auth Bypass
CVSS 8.8
CVE-2024-29837 HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 8.8
CVE-2024-0822 HIGH
ovirt-engine - Unauthenticated User Creation via CreateUserSession Command
CVSS 7.5
CVE-2023-53894 CRITICAL
phpfm 1.7.9 - Auth Bypass
CVSS 9.8
CVE-2023-41862 MEDIUM
Guido VS Contact Form <14.0 - Auth Bypass
CVSS 5.3
CVE-2023-49340 CRITICAL
Newland Nquire 1000 Interactive Kiosk <V1.00.011 - Privilege Escala...
CVSS 9.8
CVE-2023-4094 MEDIUM
Fujitsu ARCONTE Aurea 1.5.0.0 - Denial of Service via Account Lockout Bypass
CVSS 6.5
CVE-2023-41900 LOW
Eclipse Jetty 9.4.21-9.4.51, 10.0.15, 11.0.15 - Weak Authentication via OpenIdAuthenticator LoginService Bypass
CVSS 3.5
CVE-2023-24890 MEDIUM
Microsoft OneDrive - Privilege Escalation
CVSS 6.5
CVE-2022-45860 MEDIUM
FortiNAC 7.2.0, 8.7-9.4.2 and FortiNAC-F 7.2.0 - Unauthenticated Weak Authentication in Device Registration
CVSS 5.3
CVE-2022-43400 CRITICAL
Siveillance Video Mobile Server <V2022 R2 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 86