CWE-592 · 21 записей
DEPRECATED: Authentication Bypass Issues
CVE этого класса
21 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2018-10933Готовый эксплойт | A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.libssh · libssh · CWE-592 | Критическая9,1 | — | 91,8 % | 17 окт. 2018 г. |
41В плане | CVE-2018-14643Эксплойта нет | An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.theforeman · foreman · CWE-592 | Критическая9,8 | — | 6,1 % | 21 сент. 2018 г. |
40В плане | CVE-2014-5432Эксплойта нет | Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible viabaxter · sigma spectrum infusion system firmware · CWE-592 | Критическая9,8 | — | 2,6 % | 26 мар. 2019 г. |
40В плане | CVE-2018-1085Эксплойта нет | openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to redhat · openshift container platform · CWE-592 | Критическая9,8 | — | 2,2 % | 15 июн. 2018 г. |
39Наблюдать | CVE-2019-3899Эксплойта нет | It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misusredhat · openshift container platform · CWE-592 | Критическая9,8 | — | 1,4 % | 22 апр. 2019 г. |
39Наблюдать | CVE-2026-43512Proof of concept | Apache Tomcat: Digest authenticator will authenticate any unknown userapache · tomcat · CWE-592 | Критическая9,8 | — | 1,3 % | 12 мая 2026 г. |
37Наблюдать | CVE-2017-2684Эксплойта нет | Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network accesssiemens · simatic logon · CWE-592 | Критическая9,0 | — | 2,0 % | 21 февр. 2017 г. |
35Наблюдать | CVE-2018-10847Эксплойта нет | prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.prosody · prosody · CWE-592 | Высокая8,8 | — | 1,7 % | 30 июл. 2018 г. |
35Наблюдать | CVE-2019-14843Эксплойта нет | A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester.redhat · single sign-on · CWE-592 | Высокая8,8 | — | 1,2 % | 7 янв. 2020 г. |
34Наблюдать | CVE-2017-2650Эксплойта нет | It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commjenkins · pipeline classpath step · CWE-592 | Высокая8,5 | — | 1,1 % | 27 июл. 2018 г. |
32Наблюдать | CVE-2016-8371Proof of concept | The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.phoenixcontact · ilc plcs firmware · CWE-592 | Высокая7,3 | — | 10,9 % | 5 апр. 2018 г. |
32Наблюдать | CVE-2019-10201Эксплойта нет | It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures.redhat · keycloak · CWE-592 | Высокая8,1 | — | 0,7 % | 14 авг. 2019 г. |
30Наблюдать | CVE-2012-4688Эксплойта нет | I-GEN opLYNX Central Authentication Bypassi-gen · oplynx · CWE-592 | Высокая7,5 | — | 1,6 % | 31 дек. 2012 г. |
30Наблюдать | CVE-2017-7537Эксплойта нет | It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package beforredhat · enterprise linux desktop · CWE-592 | Высокая7,5 | — | 1,5 % | 26 июл. 2018 г. |
28Наблюдать | CVE-2017-7536Эксплойта нет | In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, whiredhat · hibernate validator · CWE-592 | Высокая7,0 | — | 0,5 % | 10 янв. 2018 г. |
27Наблюдать | CVE-2023-30971Эксплойта нет | Gaia unauthenticated endpointspalantir · com.palantir.acme.gaia:gaia · CWE-592 | Средняя6,8 | — | 0,2 % | 19 дек. 2025 г. |
26Наблюдать | CVE-2019-10198Эксплойта нет | An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7.theforeman · foreman-tasks · CWE-592 | Средняя6,5 | — | 1,6 % | 31 июл. 2019 г. |
25Наблюдать | CVE-2017-12164Эксплойта нет | A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin.gnome · gnome display manager · CWE-592 | Средняя6,4 | — | 0,4 % | 26 июл. 2018 г. |
25Наблюдать | CVE-2024-42759Эксплойта нет | An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.ellevo · ellevo · CWE-592 | Средняя6,3 | — | 0,4 % | 9 сент. 2024 г. |
24Наблюдать | CVE-2016-8616Эксплойта нет | A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and passhaxx · curl · CWE-592 | Средняя5,9 | — | 3,5 % | 1 авг. 2018 г. |
17Наблюдать | CVE-2014-2367Эксплойта нет | Advantech WebAccess Authentication Bypass Issuesadvantech · advantech webaccess · CWE-592 | Средняя4,3 | — | 1,5 % | 19 июл. 2014 г. |
- CVE-2018-1093364На этой неделе
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.
КритическаяCVSS 9,1Готовый эксплойтEPSS 92 %libssh · libssh17 окт. 2018 г.
- CVE-2018-1464341В плане
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %theforeman · foreman21 сент. 2018 г.
- CVE-2014-543240В плане
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %baxter · sigma spectrum infusion system firmware26 мар. 2019 г.
- CVE-2018-108540В плане
openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %redhat · openshift container platform15 июн. 2018 г.
- CVE-2019-389939Наблюдать
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misus
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redhat · openshift container platform22 апр. 2019 г.
- CVE-2026-4351239Наблюдать
Apache Tomcat: Digest authenticator will authenticate any unknown user
КритическаяCVSS 9,8Proof of conceptEPSS 1 %apache · tomcat12 мая 2026 г.
- CVE-2017-268437Наблюдать
Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %siemens · simatic logon21 февр. 2017 г.
- CVE-2018-1084735Наблюдать
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %prosody · prosody30 июл. 2018 г.
- CVE-2019-1484335Наблюдать
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %redhat · single sign-on7 янв. 2020 г.
- CVE-2017-265034Наблюдать
It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM comm
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %jenkins · pipeline classpath step27 июл. 2018 г.
- CVE-2016-837132Наблюдать
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.
ВысокаяCVSS 7,3Proof of conceptEPSS 11 %phoenixcontact · ilc plcs firmware5 апр. 2018 г.
- CVE-2019-1020132Наблюдать
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %redhat · keycloak14 авг. 2019 г.
- CVE-2012-468830Наблюдать
I-GEN opLYNX Central Authentication Bypass
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %i-gen · oplynx31 дек. 2012 г.
- CVE-2017-753730Наблюдать
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package befor
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redhat · enterprise linux desktop26 июл. 2018 г.
- CVE-2017-753628Наблюдать
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, whi
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %redhat · hibernate validator10 янв. 2018 г.
- CVE-2023-3097127Наблюдать
Gaia unauthenticated endpoints
СредняяCVSS 6,8Эксплойта нетEPSS 0 %palantir · com.palantir.acme.gaia:gaia19 дек. 2025 г.
- CVE-2019-1019826Наблюдать
An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %theforeman · foreman-tasks31 июл. 2019 г.
- CVE-2017-1216425Наблюдать
A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin.
СредняяCVSS 6,4Эксплойта нетEPSS 0 %gnome · gnome display manager26 июл. 2018 г.
- CVE-2024-4275925Наблюдать
An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.
СредняяCVSS 6,3Эксплойта нетEPSS 0 %ellevo · ellevo9 сент. 2024 г.
- CVE-2016-861624Наблюдать
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and pass
СредняяCVSS 5,9Эксплойта нетEPSS 3 %haxx · curl1 авг. 2018 г.
- CVE-2014-236717Наблюдать
Advantech WebAccess Authentication Bypass Issues
СредняяCVSS 4,3Эксплойта нетEPSS 2 %advantech · advantech webaccess19 июл. 2014 г.