CWE-288
660 CVEs • Abstraction: Base
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
CVEs (660)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user. |
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized c...Show more |
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical...Show more |
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature v...Show more |
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible |
1Hpe 2Integrated Lights Out 5 Firmware Integrated Lights Out 6 FirmwareJun 17, 2026 Dec 19, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass. |
An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack of any authentication method, resulting in the alteration or creation o...Show more |
The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plu...Show more |
1Redlioncontrols 6St Ipm 6350 Firmware St Ipm 8460 FirmwareVt Ipm2m 113 D Firmware+3 moreJun 17, 2026 Nov 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will si...Show more |
The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows un...Show more |
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This mak...Show more |
1Cisco 3Adaptive Security Appliance Software Firepower Threat DefenseSecure Firewall Threat DefenseAug 11, 2026 Nov 1, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configu...Show more |
1F5 20Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+17 moreJun 17, 2026 Oct 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system command...Show more |
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request. |
1Pingidentity 1Pingone Mfa Integration Kit Jun 17, 2026 Oct 25, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability...Show more |
1Ibm 1Sterling Partner Engagement Manager Jun 17, 2026 Oct 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896. |
WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface. |
1Rightpress 1Woocommerce Dynamic Pricing & Discounts Jun 17, 2026 Oct 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including, 2.4.1. This is due to missing authorization on the export() function w...Show more |
A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and p...Show more |