CWE-305

Authentication Bypass by Primary Weakness

Parent: CWE-1390 - Weak Authentication

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

138 vulnerabilities with CWE-305
CVE-2024-20378 HIGH
Cisco IP Phone - Info Disclosure
CVSS 7.5
CVE-2024-3847 MEDIUM
Google Chrome <124.0.6367.60 - Auth Bypass
CVSS 6.1
CVE-2024-1202 CRITICAL
XPodas Octopod <1 - Auth Bypass
CVSS 9.8
CVE-2024-1403 CRITICAL
Progress Openedge < 11.7.19 - Authentication Bypass
CVSS 10.0
CVE-2024-20015 HIGH
telephony - Privilege Escalation
CVSS 7.8
CVE-2024-20674 HIGH
Windows Kerberos - Privilege Escalation
CVSS 8.8
CVE-2023-46611 MEDIUM
YOP Poll <6.5.28 - Auth Bypass
CVSS 5.3
CVE-2023-20154 CRITICAL
Cisco Modeling Labs - Auth Bypass
CVSS 9.1
CVE-2023-41920 CRITICAL
Kiloview P1/P2 - Authentication Bypass via Hardcoded IP
CVSS 9.8
CVE-2023-4727 HIGH
dogtag-pki/pki-core - Auth Bypass
CVSS 7.5
CVE-2023-6153 CRITICAL
TeoSOFT Software TeoBASE <20240327 - Auth Bypass
CVSS 9.8
CVE-2023-7103 CRITICAL
Zksoftware Uface 5 < 12022024 - Authentication Bypass
CVSS 9.8
CVE-2023-6998 HIGH
CoolKit Technology eWeLink <5.2.0 - Privilege Escalation
CVSS 7.7
CVE-2023-4939 MEDIUM
Salesmanago < 3.2.4 - Authentication Bypass
CVSS 5.3
CVE-2023-4501 CRITICAL
OpenText (Micro Focus) Visual COBOL <9.0 - Auth Bypass
CVSS 9.8
CVE-2023-4898 HIGH
mintplex-labs/anything-llm <0.0.1 - Auth Bypass
CVSS 7.5
CVE-2023-36497 HIGH
Dover Fueling Solutions MAGLINK LX Web Console Configuration <3.3 -...
CVSS 8.8
CVE-2023-2959 HIGH
Olivaekspertiz Oliva Ekspertiz < 1.2 - Authentication Bypass
CVSS 7.5
CVE-2023-34137 CRITICAL
SonicWall GMS <9.3.2-SP1 & Analytics <2.5.0.4-R7 - Auth Bypass
CVSS 9.8
CVE-2023-34124 CRITICAL
SonicWall GMS <9.3.2-SP1 & Analytics <2.5.0.4-R7 - Auth Bypass
CVSS 9.8
CVE-2023-28126 MEDIUM
Ivanti Avalanche < 6.3.4.153 - Race Condition
CVSS 5.9
CVE-2023-1833 CRITICAL
DTS Electronics Redline Router <7.17 - Auth Bypass
CVSS 9.8
CVE-2023-28727 CRITICAL
Panasonic AiSEG2 <2.93A - Auth Bypass
CVSS 9.6
CVE-2023-27538 MEDIUM
Haxx Libcurl < 8.0.0 - Authentication Bypass
CVSS 5.5
CVE-2023-27536 MEDIUM
Haxx Libcurl < 7.88.1 - Authentication Bypass
CVSS 5.9
Details
Vulnerabilities 138