CWE-305
165 CVEs • Abstraction: Base
Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
CVEs (165)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Doverfuelingsolutions 1Maglink Lx Web Console Configuration Jun 17, 2026 Sep 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3
could allow a guest user to elevate to admin privileges. |
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users.
This issue affects Oliva Expertise EKS: before 1.2. |
1Sonicwall 2Analytics Global Management SystemJun 17, 2026 Jul 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass vulnerability. This issue affects GMS: 9.3.2-SP1 and earlier versions;...Show more |
1Sonicwall 2Analytics Global Management SystemJun 17, 2026 Jul 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier...Show more |
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication mes...Show more |
1Pingidentity 3Pingfederate Pingid Integration KitRadius PcvJun 17, 2026 Apr 25, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations. |
Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.
This issue affects Redline Router: before 7.17. |
Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers. |
6Broadcom DebianFedoraproject+3 more11Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+8 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcur...Show more |
5Debian FedoraprojectHaxx+2 more10Active Iq Unified Manager Debian LinuxFedora+7 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the...Show more |
5Debian FedoraprojectHaxx+2 more10Active Iq Unified Manager Debian LinuxFedora+7 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in...Show more |
maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentica...Show more |
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13. |
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. |
2Openstack Redhat4Barbican OpenstackOpenstack For Ibm Power+1 moreJun 17, 2026 Jan 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. |
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5. |
Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system w...Show more |
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service. |
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain...Show more |
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information. |