CWE-305
153 CVEs • Abstraction: Base
Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
CVEs (153)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Kongchuanhujiao Project 1Kongchuanhujiao Jun 17, 2026 Mar 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21. |
A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jet...Show more |
1Abb 2Symphony + Historian Symphony + OperationsJun 17, 2026 Dec 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having th...Show more |
1Siemens 1Simatic Hmi United Comfort Panels Firmware Jun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a...Show more |
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restart the host computer a...Show more |
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to inter...Show more |
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specif...Show more |
MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an admin access key, it is possible to perform admin API operations i.e. creating new service accounts...Show more |
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if inv...Show more |
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted. |
3Fedoraproject OpensuseSamba3Fedora LeapSambaJun 17, 2026 Nov 6, 2019 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory D...Show more |
1Juniper 1Identity Management Service Jun 17, 2026 Apr 10, 2019 N/A· v4 4.2 MEDIUM· v3 1.9 LOW· v2 Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associated SRX services gateways. This may allow an attacker with physical access to an existing domain conn...Show more |
4Canonical FedoraprojectMod Auth Mellon Project+1 more10Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Mar 26, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), a...Show more |