CWE-305

Authentication Bypass by Primary Weakness

Parent: CWE-1390 - Weak Authentication

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

154 vulnerabilities with CWE-305
CVE-2024-10394 HIGH
OpenAFS < 1.6.25 - Authentication Bypass via PAG Throttling Mechanism
CVSS 7.8
CVE-2024-10082 HIGH
CodeChecker <6.24.1 - Privilege Escalation
CVSS 8.7
CVE-2024-50478 CRITICAL
Swoop 1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass
CVSS 9.8
CVE-2024-9683 MEDIUM
Quay - Authentication Bypass via Truncated Password
CVSS 4.8
CVE-2024-20463 MEDIUM
Cisco ATA 190 Series - Unauthenticated RCE
CVSS 5.4
CVE-2024-8642 HIGH
Eclipse Dataspace Components <0.9.0 - Auth Bypass
CVSS 8.1
CVE-2024-5957 MEDIUM
Trellix Intrusion Prevention System Manager < 11.1.7.97 - Unauthenticated Authentication Bypass
CVSS 6.3
CVE-2024-5956 MEDIUM
Trellix Intrusion Prevention System Manager - Unauthenticated Authentication Bypass
CVSS 6.5
CVE-2024-7557 HIGH
Red Hat OpenShift AI - Authentication Bypass and Privilege Escalation via ServiceAccount Token Exposure
CVSS 8.8
CVE-2024-4784 MEDIUM
GitLab EE <17.0.6-17.2.2 - Auth Bypass
CVSS 4.2
CVE-2024-6637 HIGH
WooCommerce - Social Login <2.7.3 - Privilege Escalation
CVSS 7.3
CVE-2024-38433 MEDIUM
Nuvoton NPCM7xx Firmware < 10.10.19 - Authentication Bypass and Arbitrary Code Execution via U-Boot Image Header
CVSS 6.7
CVE-2024-39899 MEDIUM
PrivateBin 1.5.0-1.7.3 - Authentication Bypass via YOURLS Proxy URL Validation
CVSS 5.3
CVE-2024-37085 MEDIUM KEV
VMware ESXi - Authentication Bypass via Recreated Active Directory Group
CVSS 6.8
CVE-2024-36388 CRITICAL
MileSight DeviceHub - Info Disclosure
CVSS 10.0
CVE-2024-34077 HIGH
MantisBT < 2.26.2 - Unauthenticated Account Takeover via Password Reset Token Reuse
CVSS 7.3
CVE-2024-20378 HIGH
Cisco IP Phone 6821/6841/6851/6861/6871/7811 < 12.0.4 - Unauthenticated Information Disclosure
CVSS 7.5
CVE-2024-3847 MEDIUM
Google Chrome <124.0.6367.60 - Auth Bypass
CVSS 6.1
CVE-2024-1202 CRITICAL
XPodas Octopod < v1 - Authentication Bypass
CVSS 9.8
CVE-2024-1403 CRITICAL
OpenEdge < 11.7.19 - Authentication Bypass via Credential Handling Failure
CVSS 10.0
CVE-2024-20015 HIGH
Android - Local Privilege Escalation via Telephony Permissions Bypass
CVSS 7.8
CVE-2024-20674 HIGH
Windows Kerberos - Privilege Escalation
CVSS 8.8
CVE-2023-46611 MEDIUM
YOP Poll < 6.5.28 - Authentication Bypass via Broken CAPTCHA Control
CVSS 5.3
CVE-2023-20154 CRITICAL
Cisco Modeling Labs 2.3-2.5.1 - Authentication Bypass via External Auth Server Message Handling
CVSS 9.1
CVE-2023-41920 CRITICAL
Kiloview P1/P2 - Authentication Bypass via Hardcoded IP
CVSS 9.8
Details
Vulnerabilities 154