CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2023-6718 CRITICAL
Repox - Unauthenticated User Creation and Modification via Crafted POST Request
CVSS 9.4
CVE-2023-2437 CRITICAL
UserPro < 5.1.1 - Unauthenticated Authentication Bypass via Facebook Login
CVSS 9.8
CVE-2023-42770 CRITICAL
Redlioncontrols St-ipm-6350 Firmware - Missing Authentication
CVSS 10.0
CVE-2023-3277 CRITICAL
MStore API < 4.10.7 - Unauthenticated Account Access and Privilege Escalation via Apple Login Feature
CVSS 9.8
CVE-2023-41351 CRITICAL
Chunghwa Telecom NOKIA G-040W-Q - Auth Bypass
CVSS 9.8
CVE-2023-20247 MEDIUM
Cisco Adaptive Security Appliance Software - Authentication Bypass via Remote Access SSL VPN
CVSS 5.0
CVE-2023-46747 CRITICAL KEV
F5 BIG-IP 13.1.0-13.1.4 - Unauthenticated Remote Command Execution via Configuration Utility Bypass
CVSS 9.8
CVE-2023-39930 HIGH
PingID Radius PCV 3.0.0-3.0.3 - Unauthenticated First-Factor Authentication Bypass via Malicious RADIUS Client Request
CVSS 7.5
CVE-2023-39231 HIGH
PingFederate PingOne MFA Integration Kit - Missing Authentication for MFA Device Pairing
CVSS 7.3
CVE-2023-43045 MEDIUM
IBM Sterling Partner Engagement Manager <6.2.2 - Privilege Escalation
CVSS 5.9
CVE-2023-46319 HIGH
WALLIX Bastion <9.0.9, <10.0.5 - Info Disclosure
CVSS 7.5
CVE-2023-4957 MEDIUM
Zebra ZT410 Firmware - Authentication Bypass via setvarsResults.cgi POST Request
CVSS 5.4
CVE-2023-42771 HIGH
FurunoSystems ACERA 1310 and 1320 Firmware < 01.26 - Unauthenticated Authentication Bypass
CVSS 8.8
CVE-2023-1260 HIGH
kube-apiserver - Authentication Bypass via Ephemeral Containers Subresource
CVSS 8.0
CVE-2023-42793 CRITICAL KEV
JetBrains TeamCity < 2023.05.4 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-4702 CRITICAL
Yepas Digital Yepas < 1.0.1 - Authentication Bypass
CVSS 9.8
CVE-2023-41256 CRITICAL
Doverfuelingsolutions Maglink LX Web Console Configuration - Authentication Bypass
CVSS 9.1
CVE-2023-20269 MEDIUM KEV
Cisco Adaptive Security Appliance Software - Authentication Bypass via Default Connection Profile
CVSS 5.0
CVE-2023-3162 CRITICAL
Stripe Payment Plugin for WooCommerce <3.7.7 - Auth Bypass
CVSS 9.8
CVE-2023-32002 CRITICAL
Node.js 16.0.0-16.20.1 - Policy Mechanism Bypass via Module._load()
CVSS 9.8
CVE-2023-3249 CRITICAL
Web3 - Crypto wallet Login & NFT token gating <= 2.6.0 - Authenticated Authentication Bypass via Hidden Form Data
CVSS 9.8
CVE-2023-2834 CRITICAL
BookIt WordPress <2.3.7 - Auth Bypass
CVSS 9.8
CVE-2023-30946 LOW
palantir/foundry_issues < 2.497.0 - Unauthenticated Metadata Exposure via Notification API
CVSS 3.5
CVE-2023-2982 CRITICAL
WordPress Social Login and Register <= 7.6.4 - Authentication Bypass via Insufficient Encryption
CVSS 9.8
CVE-2023-34335 HIGH
AMI MegaRAC SPX 12.0-12.7 - Unauthenticated SPI Flash Write via IPMI Handler
CVSS 7.7
Details
Vulnerabilities 612