CWE-302
43 CVEs • Abstraction: Base
Authentication Bypass by Assumed-Immutable Data
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
CVEs (43)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Unified Communications Manager Jun 17, 2026 Apr 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attac...Show more |
1Openvpn 1Openvpn Access Server Jun 17, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp...Show more |
1Jqueryform 1Php Formmail Generator Nov 21, 2024 Jul 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by navigating directly to /admin.php?mod=admin&func=panel |