CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2021-32958
MEDIUM
Claroty Secure Remote Access Site <3.2 - Privilege Escalation
CVSS 5.5
CVE-2021-31559
HIGH
Splunk Enterprise Indexer <8.1.5, <8.2.1 - Auth Bypass
CVSS 7.5
CVE-2021-41992
HIGH
PingID Integration for Windows Login < 2.7 - Offline MFA Bypass via RSA Misconfiguration
CVSS 7.7
CVE-2021-3897
CRITICAL
Lenovo Fan Power Controller2/FPC2 - Auth Bypass
CVSS 9.8
CVE-2021-3849
CRITICAL
Lenovo Fan Power Controller2/FPC2 - Auth Bypass
CVSS 9.8
CVE-2021-32986
CRITICAL
Automation Direct CLICK PLC CPU <3.00 - Privilege Escalation
CVSS 9.8
CVE-2021-32984
CRITICAL
Automation Direct CLICK PLC <v3.00 - Privilege Escalation
CVSS 9.8
CVE-2021-32980
CRITICAL
Automation Direct CLICK PLC CPU <3.00 - Privilege Escalation
CVSS 9.8
CVE-2021-34977
HIGH
NETGEAR R7000 Firmware 1.0.11.116_10.2.100 - Unauthenticated Authentication Bypass via SOAP Request
CVSS 8.8
CVE-2021-33017
HIGH
Philips IntelliBridge EC40 and EC80 Firmware < c.00.04 - Unauthenticated Authentication Bypass via Alternate Path
CVSS 8.1
CVE-2021-43985
CRITICAL
mySCADA myPRO <8.20.0 - Info Disclosure
CVSS 9.1
CVE-2021-21952
CRITICAL
Anker Eufy Homebase 2 2.1.6.9h - Authentication Bypass via CMD_DEVICE_GET_RSA_KEY_REQUEST
CVSS 9.8
CVE-2021-27453
HIGH
Mesa Labs AmegaView <3.0 - Auth Bypass
CVSS 7.3
CVE-2021-43935
HIGH
Welch Allyn Connex Cardio < 1.1.1 - Improper Authentication via SSO Manual Account Entry
CVSS 8.1
CVE-2021-36308
MEDIUM
Networking OS10 <October 2021 - Auth Bypass
CVSS 5.9
CVE-2021-41292
CRITICAL
ECOA BAS Controller - Unauthenticated Authentication Bypass via Cookie Poisoning
CVSS 9.8
CVE-2021-33700
HIGH
SAP Business One <10.0 - Auth Bypass
CVSS 7.8
CVE-2021-32967
CRITICAL
Delta Electronics DIAEnergie <1.7.5 - Privilege Escalation
CVSS 9.8
CVE-2021-28131
HIGH
Apache Impala < 4.0.0 - Authenticated Session Hijacking via Logged Session Secrets
CVSS 7.5
CVE-2020-37255
HIGH
WordPress Time Capsule Plugin 1.21.16 Authentication Bypass
CVSS 7.5
CVE-2020-37156
MEDIUM
BloodX 1.0 - Unauthenticated Authentication Bypass via Crafted Payload in login.php
CVSS 6.5
CVE-2020-36724
CRITICAL
Wordable plugin <3.1.1 - Auth Bypass
CVSS 9.8
CVE-2020-36713
CRITICAL
MStore API < 2.1.5 - Unauthenticated Authentication Bypass via Unrestricted Register and Update User Profile Routes
CVSS 9.8
CVE-2020-27866
HIGH
NETGEAR Multiple Routers Firmware - Unauthenticated Authentication Bypass via mini_httpd
CVSS 8.8
CVE-2020-27865
HIGH
D-Link DAP-1860 Firmware < 1.04b03 - Unauthenticated Remote Code Execution via uhttpd String Matching Flaw
CVSS 8.8
Details
Vulnerabilities
612