CWE-291 · 11 records
Reliance on IP Address for Authentication
CVEs in this class
11 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2025-34202No exploit | Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WANvasion · virtual appliance application · CWE-291 | High8.7 | — | 1.0% | Sep 19, 2025 |
32Monitor | CVE-2023-7211No exploit | Uniway Router Administrative Web Interface reliance on ip address for authenticationuniwayinfo · uw-302vp firmware · CWE-291 | High8.1 | — | 0.9% | Jan 7, 2024 |
32Monitor | CVE-2024-23309No exploit | The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on clielevel1 · wbr-6012 firmware · CWE-291 | High8.1 | — | 0.9% | Oct 30, 2024 |
30Monitor | CVE-2025-59101No exploit | Insufficient Session Management in dormakaba access managerdormakaba · access manager 92xx-k5 · CWE-291 | High7.7 | — | 0.8% | Jan 26, 2026 |
30Monitor | CVE-2023-35906No exploit | IBM Aspera Faspex security bypassibm · aspera faspex · CWE-291 | High7.5 | — | 0.4% | Sep 4, 2023 |
29Monitor | CVE-2026-3690No exploit | OpenClaw Canvas Authentication Bypass Vulnerabilityopenclaw · openclaw · CWE-291 | High7.4 | — | 0.6% | Apr 10, 2026 |
27Monitor | CVE-2025-66602No exploit | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.yokogawa · fast\/tools · CWE-291 | Medium6.9 | — | 0.4% | Feb 9, 2026 |
23Monitor | CVE-2022-46415No exploit | DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.dji · spark firmware · CWE-291 | Medium5.9 | — | 0.9% | Mar 27, 2023 |
23Monitor | GHSA-hx53-jchx-cr52No exploit | Symfony2 improper IP based access controlPackagist · symfony/symfony · CWE-291 | Medium5.9 | — | — | May 30, 2024 |
16Monitor | CVE-2024-32765No exploit | A vulnerability has been reported to affect Network & Virtual Switch.qnap · qts · CWE-291 | Medium4.2 | — | 0.2% | Aug 12, 2024 |
13Monitor | CVE-2026-86485No exploit | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooksjetbrains · youtrack · CWE-291 | Low3.3 | — | 0.2% | Sep 7, 2026 |
- CVE-2025-3420234Monitor
Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
HighCVSS 8.7No exploitEPSS 1%vasion · virtual appliance applicationSep 19, 2025
- CVE-2023-721132Monitor
Uniway Router Administrative Web Interface reliance on ip address for authentication
HighCVSS 8.1No exploitEPSS 1%uniwayinfo · uw-302vp firmwareJan 7, 2024
- CVE-2024-2330932Monitor
The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on clie
HighCVSS 8.1No exploitEPSS 1%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2025-5910130Monitor
Insufficient Session Management in dormakaba access manager
HighCVSS 7.7No exploitEPSS 1%dormakaba · access manager 92xx-k5Jan 26, 2026
- CVE-2023-3590630Monitor
IBM Aspera Faspex security bypass
HighCVSS 7.5No exploitEPSS 0%ibm · aspera faspexSep 4, 2023
- CVE-2026-369029Monitor
OpenClaw Canvas Authentication Bypass Vulnerability
HighCVSS 7.4No exploitEPSS 1%openclaw · openclawApr 10, 2026
- CVE-2025-6660227Monitor
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
MediumCVSS 6.9No exploitEPSS 0%yokogawa · fast\/toolsFeb 9, 2026
- CVE-2022-4641523Monitor
DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.
MediumCVSS 5.9No exploitEPSS 1%dji · spark firmwareMar 27, 2023
- GHSA-hx53-jchx-cr5223Monitor
Symfony2 improper IP based access control
MediumCVSS 5.9No exploitPackagist · symfony/symfonyMay 30, 2024
- CVE-2024-3276516Monitor
A vulnerability has been reported to affect Network & Virtual Switch.
MediumCVSS 4.2No exploitEPSS 0%qnap · qtsAug 12, 2024
- CVE-2026-8648513Monitor
In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
LowCVSS 3.3No exploitEPSS 0%jetbrains · youtrackSep 7, 2026