CWE-288
659 CVEs • Abstraction: Base
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
CVEs (659)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ibm Lenovo5Nextscale Fan Power Controller Firmware Nextscale N1200 Enclosure FirmwareThinkagile Hx Enclosure Certified Node Firmware+2 moreJun 17, 2026 Apr 22, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated att...Show more |
2Ibm Lenovo5Nextscale Fan Power Controller Firmware Nextscale N1200 Enclosure FirmwareThinkagile Hx Enclosure Certified Node Firmware+2 moreJun 17, 2026 Apr 22, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to exe...Show more |
1Siteground 1Security Optimizer Jun 17, 2026 Apr 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allo...Show more |
1Juniper 1Contrail Service Orchestration Jun 17, 2026 Apr 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated without authentication thereby taking contro...Show more |
Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting. |
1Automationdirect 20C0 10are D Firmware C0 10dd1e D FirmwareC0 10dd2e D Firmware+17 moreJun 17, 2026 Apr 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains u...Show more |
1Automationdirect 20C0 10are D Firmware C0 10dd1e D FirmwareC0 10dd2e D Firmware+17 moreJun 17, 2026 Apr 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked b...Show more |
1Automationdirect 20C0 10are D Firmware C0 10dd1e D FirmwareC0 10dd2e D Firmware+17 moreJun 17, 2026 Apr 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to the PLC while an existing connection is al...Show more |
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this...Show more |
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within t...Show more |
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The spec...Show more |
1Philips 2Intellibridge Ec40 Firmware Intellibridge Ec80 FirmwareJun 17, 2026 Dec 27, 2021 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication. |
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization. |
1Anker 1Eufy Homebase 2 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to incr...Show more |
Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application, which may allow an attacker to gain access. |
1Baxter 7Welch Allyn Connex Cardio Welch Allyn Diagnostic Cardiology SuiteWelch Allyn Hscribe Holter Analysis System Firmware+4 moreJun 17, 2026 Dec 15, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provision...Show more |
Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to gain access and p...Show more |
1Ecoa 3Ecs Router Controller Ecs Firmware Riskbuster FirmwareRiskterminatorJun 17, 2026 Sep 30, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical...Show more |
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sens...Show more |
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with admini...Show more |