CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

569 vulnerabilities with CWE-288
CVE-2024-27198 CRITICAL KEV
TeamCity < 2023.11.4 - Authentication Bypass
CVSS 9.8
CVE-2024-1525 MEDIUM
GitLab CE/EE <16.7.6-16.8.3-16.9.1 - Auth Bypass
CVSS 5.3
CVE-2024-1709 CRITICAL KEV
ConnectWise ScreenConnect < 23.9.8 - Authentication Bypass
CVSS 10.0
CVE-2024-21491 MEDIUM
svix-webhooks < 1.17.0 - Authentication Bypass via Signature Length Mismatch
CVSS 5.9
CVE-2024-23917 CRITICAL
JetBrains TeamCity > 2023.11.3 - Authentication Bypass
CVSS 9.8
CVE-2023-49564 HIGH
Nokia CBIS/NCS - Unauthenticated Authentication Bypass via Crafted HTTP Header
CVSS 8.8
CVE-2023-37057 CRITICAL
Jlink AX1800 1.0 - Remote Code Execution via Authentication Mechanism
CVSS 9.8
CVE-2023-50915 MEDIUM
GOG Galaxy (Beta) <2.0.71.2 - Privilege Escalation
CVSS 6.5
CVE-2023-50272 HIGH
HPE Integrated Lights-Out 5 2.63-3.00 and iLO 6 1.05-1.55 - Authentication Bypass
CVSS 7.5
CVE-2023-6718 CRITICAL
Repox - Unauthenticated User Creation and Modification via Crafted POST Request
CVSS 9.4
CVE-2023-2437 CRITICAL
UserPro < 5.1.1 - Unauthenticated Authentication Bypass via Facebook Login
CVSS 9.8
CVE-2023-42770 CRITICAL
Redlioncontrols St-ipm-6350 Firmware - Missing Authentication
CVSS 10.0
CVE-2023-3277 CRITICAL
MStore API < 4.10.7 - Unauthenticated Account Access and Privilege Escalation via Apple Login Feature
CVSS 9.8
CVE-2023-41351 CRITICAL
Chunghwa Telecom NOKIA G-040W-Q - Auth Bypass
CVSS 9.8
CVE-2023-20247 MEDIUM
Cisco Adaptive Security Appliance Software - Authentication Bypass via Remote Access SSL VPN
CVSS 5.0
CVE-2023-46747 CRITICAL KEV
F5 BIG-IP 13.1.0-13.1.4 - Unauthenticated Remote Command Execution via Configuration Utility Bypass
CVSS 9.8
CVE-2023-39930 HIGH
PingID Radius PCV 3.0.0-3.0.3 - Unauthenticated First-Factor Authentication Bypass via Malicious RADIUS Client Request
CVSS 7.5
CVE-2023-39231 HIGH
PingFederate PingOne MFA Integration Kit - Missing Authentication for MFA Device Pairing
CVSS 7.3
CVE-2023-43045 MEDIUM
IBM Sterling Partner Engagement Manager <6.2.2 - Privilege Escalation
CVSS 5.9
CVE-2023-46319 HIGH
WALLIX Bastion <9.0.9, <10.0.5 - Info Disclosure
CVSS 7.5
CVE-2023-4957 MEDIUM
Zebra ZT410 Firmware - Authentication Bypass via setvarsResults.cgi POST Request
CVSS 5.4
CVE-2023-42771 HIGH
FurunoSystems ACERA 1310 and 1320 Firmware < 01.26 - Unauthenticated Authentication Bypass
CVSS 8.8
CVE-2023-1260 HIGH
kube-apiserver - Authentication Bypass via Ephemeral Containers Subresource
CVSS 8.0
CVE-2023-42793 CRITICAL KEV
JetBrains TeamCity < 2023.05.4 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-4702 CRITICAL
Yepas Digital Yepas < 1.0.1 - Authentication Bypass
CVSS 9.8
Details
Vulnerabilities 569