Captive Portal can allow authentication bypass
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.
CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface
when someone on the local network repeatedly requests the /accessdenied URL.
The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an
unauthorized user without permission rights has physical access to the EPAS-UI computer and is a
Servision - CWE-287: Improper Authentication
Captive Portal can expose sensitive information
Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbit
The vulnerability could be remotely exploited to bypass authentication.
An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDO
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.
An authentication bypass vulnerability exists in HPE StoreOnce Software.
A flaw exists in the Windows login flow where an AuthContext token can
be exploited for replay attacks and authentication bypass.
Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.
An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the dev
The administrator is able to configure an insecure captive portal script
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-
Page 1+ Next →