CWE-305

Authentication Bypass by Primary Weakness

Parent: CWE-1390 - Weak Authentication

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

154 vulnerabilities with CWE-305
CVE-2023-4727 HIGH
Red Hat Certificate System 10.4 EUS for RHEL-8 - Authentication Bypass via LDAP Injection
CVSS 7.5
CVE-2023-6153 CRITICAL
TeoSOFT Software TeoBASE <20240327 - Auth Bypass
CVSS 9.8
CVE-2023-7103 CRITICAL
ZKSoftware UFace 5 <= 12022024 - Authentication Bypass
CVSS 9.8
CVE-2023-6998 HIGH
CoolKit Technology eWeLink <5.2.0 - Privilege Escalation
CVSS 7.7
CVE-2023-4939 MEDIUM
SALESmanago < 3.2.4 - Unauthenticated Log Injection via Weak Callback API Token
CVSS 5.3
CVE-2023-4501 CRITICAL
OpenText (Micro Focus) Visual COBOL <9.0 - Auth Bypass
CVSS 9.8
CVE-2023-4898 HIGH
mintplex-labs/anything-llm <0.0.1 - Auth Bypass
CVSS 7.5
CVE-2023-36497 HIGH
Dover Fueling Solutions MAGLINK LX Web Console Configuration <3.3 -...
CVSS 8.8
CVE-2023-2959 HIGH
Oliva Expertise EKS < 1.2 - Authentication Bypass
CVSS 7.5
CVE-2023-34137 CRITICAL
SonicWall GMS <9.3.2-SP1 & Analytics <2.5.0.4-R7 - Auth Bypass
CVSS 9.8
CVE-2023-34124 CRITICAL
SonicWall GMS <9.3.2-SP1 & Analytics <2.5.0.4-R7 - Auth Bypass
CVSS 9.8
CVE-2023-28126 MEDIUM
Ivanti Avalanche < 6.3.4.153 - Authentication Bypass via SetUser Method or Race Condition
CVSS 5.9
CVE-2023-1833 CRITICAL
DTS Electronics Redline Router <7.17 - Auth Bypass
CVSS 9.8
CVE-2023-28727 CRITICAL
Panasonic AiSEG2 <2.93A - Auth Bypass
CVSS 9.6
CVE-2023-27538 MEDIUM
libcurl < 8.0.0 - Authentication Bypass via SSH Connection Reuse
CVSS 5.5
CVE-2023-27536 MEDIUM
libcurl < 8.0.0 - Authentication Bypass via Connection Reuse
CVSS 5.9
CVE-2023-27535 MEDIUM
libcurl < 8.0.0 - Authentication Bypass via FTP Connection Reuse
CVSS 5.9
CVE-2023-27582 CRITICAL
maddy 0.2.0-0.6.2 - Authentication Bypass via SASL PLAIN Username
CVSS 9.1
CVE-2023-1307 CRITICAL
froxlor < 2.0.13 - Authentication Bypass
CVSS 9.8
CVE-2023-0777 CRITICAL
modoboa < 2.0.4 - Authentication Bypass
CVSS 9.8
CVE-2022-48470 MEDIUM
Huawei HiLink AI Life - Authentication Bypass
CVSS 4.0
CVE-2022-40723 MEDIUM
PingFederate 11.1.0-11.1.4 and PingID Integration Kit < 2.24 - Authentication Bypass via RADIUS PCV Adapter
CVSS 6.5
CVE-2022-3100 MEDIUM
OpenStack Barbican - Authentication Bypass via API Query String
CVSS 5.9
CVE-2022-4722 HIGH
rdiffweb < 2.5.5 - Authentication Bypass
CVSS 7.2
CVE-2022-39245 HIGH
makedeb/mist < 0.9.5 - Authentication Bypass via PATH Variable Sudo Binary
CVSS 8.4
Details
Vulnerabilities 154