CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2020-27863
MEDIUM
D-Link DVA-2800 and DSL-2888A - Unauthenticated Sensitive Information Disclosure via dhttpd Service
CVSS 6.5
CVE-2020-13185
MEDIUM
Teradici Cloud Access Connector <18 - Auth Bypass
CVSS 6.5
CVE-2020-10048
MEDIUM
SIMATIC PCS 7 and WinCC < 7.5 SP2 - Improper Authentication via Insecure Password Verification
CVSS 5.5
CVE-2020-10148
CRITICAL
KEV
SolarWinds Orion Platform 2019.4 HF 5, 2020.2, 2020.2 HF 1 - Unauthenticated API Authentication Bypass
CVSS 9.8
CVE-2020-17409
MEDIUM
NETGEAR R6120- WNR2020 - Info Disclosure
CVSS 6.5
CVE-2020-10283
CRITICAL
Micro Air Vehicle Link - Authentication Bypass via Version Negotiation Downgrade
CVSS 9.8
CVE-2020-5384
HIGH
RSA MFA Agent 2.0 - Unauthenticated Authentication Bypass via Alternate Path
CVSS 8.4
CVE-2020-15633
HIGH
D-Link DIR-867,DIR-878,DIR-882 <1.20B10_BETA - Auth Bypass
CVSS 8.8
CVE-2020-14485
CRITICAL
OpenClinic GA 5.09.02 and 5.89.05b - Improper Authentication
CVSS 9.8
CVE-2020-14477
LOW
Philips ClearVue 850/350 <3.2, CX50, Affiniti 70/50 <5.0, EPIQ 7 <5.0, Sparq <3.0.2, Xperius - Improper Authentication
CVSS 3.6
CVE-2020-4050
LOW
WordPress 3.7-5.4.1 - Arbitrary User Meta Field Injection via set-screen-option Filter Misuse
CVSS 3.5
CVE-2020-6091
CRITICAL
Epson EB-1470Ui Firmware MAIN: 98009273ESWWV107 MAIN2: 8X7325WWV303 - Authentication Bypass via HTTP Request
CVSS 9.1
CVE-2020-11005
MEDIUM
WindowsHello <1.0.4 - Info Disclosure
CVSS 5.1
CVE-2020-1637
HIGH
Juniper Junos OS on SRX Series Improper Authentication via IP Address Range Configuration
CVSS 7.2
CVE-2020-1618
MEDIUM
Juniper Junos OS Authentication Bypass via Console Port
CVSS 6.3
CVE-2019-25763
CRITICAL
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
CVSS 9.8
CVE-2019-5165
HIGH
Moxa AWK-3131A Firmware 1.13 - Authentication Bypass via Hostname Processing
CVSS 7.2
CVE-2019-9510
MEDIUM
Microsoft Windows 10 <1803 and Windows Server 2019 - Privilege Esca...
CVSS 5.3
CVE-2019-5486
HIGH
GitLab <12.3.2, <12.2.6, and <12.1.10 - Authentication Bypass via Salesforce Login Integration
CVSS 8.8
CVE-2019-18250
CRITICAL
ABB Plant Connect and Power Generation Information Manager - Authentication Bypass
CVSS 9.8
CVE-2019-3758
CRITICAL
RSA Archer < 6.6.0.2 - Unauthenticated Authentication Bypass via Weak Password Requirements
CVSS 9.8
CVE-2019-5473
HIGH
GitLab - Authentication Bypass via Email Verification
CVSS 7.2
CVE-2019-13526
HIGH
Datalogic AV7000 Firmware < 4.6.0.0 - Authentication Bypass
CVSS 8.8
CVE-2019-5455
MEDIUM
Nextcloud Android app 3.6.0 - Improper Authentication via Multi-Account Creation Abort
CVSS 6.8
CVE-2019-5453
MEDIUM
Nextcloud Android App < 3.3.0 - Authentication Bypass via File Provider Switch
CVSS 6.1
Details
Vulnerabilities
612