CWE-303

Incorrect Implementation of Authentication Algorithm

Parent: CWE-1390 - Weak Authentication

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

84 vulnerabilities with CWE-303
CVE-2021-32691 HIGH
Apollos Apps <2.20.0 - Info Disclosure
CVSS 8.8
CVE-2021-21378 HIGH
Envoy - Authentication Bypass
CVSS 8.2
CVE-2020-15632 HIGH
D-Link DIR-842 3.13B05 - Auth Bypass
CVSS 8.8
CVE-2020-5268 MEDIUM
Sustainsys.Saml2 < 1.0.2 and 2.0.0-2.6.0 - Improper Authentication via Token Subject Confirmation Bypass
CVSS 6.5
CVE-2020-8863 HIGH
D-Link DIR-867,DIR-878,DIR-882 <1.10B04 - Auth Bypass
CVSS 8.8
CVE-2020-8861 HIGH
D-Link DAP-1330 1.10B01 BETA - Auth Bypass
CVSS 8.8
CVE-2019-25436 MEDIUM
Sricam DeviceViewer 3.12.0.1 - Auth Bypass
CVSS 6.5
CVE-2018-4841 CRITICAL
TIM 1531 IRC Firmware < 1.1 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2016-9463 HIGH
Nextcloud Server <9.0.54/10.0.1 & ownCloud Server <9.1.2/9.0.6/8.2.9 - SMB Auth Bypass
CVSS 8.1
Details
Vulnerabilities 84