CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2021-32958 MEDIUM
Claroty Secure Remote Access Site <3.2 - Privilege Escalation
CVSS 5.5
CVE-2021-31559 HIGH
Splunk Enterprise Indexer <8.1.5, <8.2.1 - Auth Bypass
CVSS 7.5
CVE-2021-41992 HIGH
PingID Integration for Windows Login < 2.7 - Offline MFA Bypass via RSA Misconfiguration
CVSS 7.7
CVE-2021-3897 CRITICAL
Lenovo Fan Power Controller2/FPC2 - Auth Bypass
CVSS 9.8
CVE-2021-3849 CRITICAL
Lenovo Fan Power Controller2/FPC2 - Auth Bypass
CVSS 9.8
CVE-2021-32986 CRITICAL
Automation Direct CLICK PLC CPU <3.00 - Privilege Escalation
CVSS 9.8
CVE-2021-32984 CRITICAL
Automation Direct CLICK PLC <v3.00 - Privilege Escalation
CVSS 9.8
CVE-2021-32980 CRITICAL
Automation Direct CLICK PLC CPU <3.00 - Privilege Escalation
CVSS 9.8
CVE-2021-34977 HIGH
NETGEAR R7000 Firmware 1.0.11.116_10.2.100 - Unauthenticated Authentication Bypass via SOAP Request
CVSS 8.8
CVE-2021-33017 HIGH
Philips IntelliBridge EC40 and EC80 Firmware < c.00.04 - Unauthenticated Authentication Bypass via Alternate Path
CVSS 8.1
CVE-2021-43985 CRITICAL
mySCADA myPRO <8.20.0 - Info Disclosure
CVSS 9.1
CVE-2021-21952 CRITICAL
Anker Eufy Homebase 2 2.1.6.9h - Authentication Bypass via CMD_DEVICE_GET_RSA_KEY_REQUEST
CVSS 9.8
CVE-2021-27453 HIGH
Mesa Labs AmegaView <3.0 - Auth Bypass
CVSS 7.3
CVE-2021-43935 HIGH
Welch Allyn Connex Cardio < 1.1.1 - Improper Authentication via SSO Manual Account Entry
CVSS 8.1
CVE-2021-36308 MEDIUM
Networking OS10 <October 2021 - Auth Bypass
CVSS 5.9
CVE-2021-41292 CRITICAL
ECOA BAS Controller - Unauthenticated Authentication Bypass via Cookie Poisoning
CVSS 9.8
CVE-2021-33700 HIGH
SAP Business One <10.0 - Auth Bypass
CVSS 7.8
CVE-2021-32967 CRITICAL
Delta Electronics DIAEnergie <1.7.5 - Privilege Escalation
CVSS 9.8
CVE-2021-28131 HIGH
Apache Impala < 4.0.0 - Authenticated Session Hijacking via Logged Session Secrets
CVSS 7.5
CVE-2020-37255 HIGH
WordPress Time Capsule Plugin 1.21.16 Authentication Bypass
CVSS 7.5
CVE-2020-37156 MEDIUM
BloodX 1.0 - Unauthenticated Authentication Bypass via Crafted Payload in login.php
CVSS 6.5
CVE-2020-36724 CRITICAL
Wordable plugin <3.1.1 - Auth Bypass
CVSS 9.8
CVE-2020-36713 CRITICAL
MStore API < 2.1.5 - Unauthenticated Authentication Bypass via Unrestricted Register and Update User Profile Routes
CVSS 9.8
CVE-2020-27866 HIGH
NETGEAR Multiple Routers Firmware - Unauthenticated Authentication Bypass via mini_httpd
CVSS 8.8
CVE-2020-27865 HIGH
D-Link DAP-1860 Firmware < 1.04b03 - Unauthenticated Remote Code Execution via uhttpd String Matching Flaw
CVSS 8.8
Details
Vulnerabilities 612