← Back
CWE-288

659 CVEs • Abstraction: Base

Authentication Bypass Using an Alternate Path or Channel

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

JSON object

Loading...

CVEs (659)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions...Show more
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.Show less
1Abb
2Plant Connect
Power Generation Information Manager
Jun 17, 2026
Nov 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract...Show more
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.Show less
1Rsa
1Archer
Jun 17, 2026
Sep 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could...Show more
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.
1Datalogic
1Av7000 Firmware
Jun 17, 2026
Aug 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker to remotely execute arbitrary code.
1Nextcloud
1Nextcloud
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
1Nextcloud
1Nextcloud
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Jul 30, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.
1Pangea Comm
1Fax Ata
Jun 17, 2026
Feb 28, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to cause a continual deni...Show more
Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to cause a continual denial-of-service condition.Show less
1Lcds
1Laquis Scada
Nov 21, 2024
Feb 5, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.
1Circontrol
1Circarlife Firmware
Nov 21, 2024
Nov 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
1Echelon
4I.lon 100 Firmware
I.lon 600 FirmwareSmartserver 1 Firmware+1 more
Jun 17, 2026
Jul 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security c...Show more
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product.Show less
1Navarino
1Infinity
Jun 17, 2026
Jul 24, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an information leak.
1Hughes
4Dw7000 Firmware
Hn7000s FirmwareHn7000sm Firmware+1 more
Nov 21, 2024
Jul 13, 2018
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible via telnet and does...Show more
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible via telnet and does not require authentication. An unauthenticated remote user can access many administrative commands via this interface, including rebooting the modem.Show less
1Siemens
2Siclock Tc100 Firmware
Siclock Tc400 Firmware
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could potentially circumvent the authentication mechanism if he/she is a...Show more
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could potentially circumvent the authentication mechanism if he/she is able to obtain certain knowledge specific to the attacked device.Show less
2Debian
Gluster
2Debian Linux
Glusterfs
Nov 21, 2024
Jun 20, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privile...Show more
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.Show less
1Siemens
17kt Pac1200 Data Manager Firmware
May 13, 2026
Dec 27, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to...Show more
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations over the network.Show less
1Siemens
2Simatic Wincc Sm@rtclient
Simatic Wincc Sm@rtclient Lite
May 13, 2026
Aug 8, 2017
N/A· v4
5.4 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical acce...Show more
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.Show less
1Geutebruck
1Ip Camera G Cam Efd 2250 Firmware
May 13, 2026
May 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attack...Show more
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control that may allow remote code execution.Show less