Vulnerabilities > Authentication Bypass Using an Alternate Path or Channel

DATE CVE VULNERABILITY TITLE RISK
2023-09-11 CVE-2023-41256 Authentication Bypass Using an Alternate Path or Channel vulnerability in Doverfuelingsolutions Maglink LX web Console Configuration
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access.
network
low complexity
doverfuelingsolutions CWE-288
critical
9.1
2022-07-25 CVE-2022-35869 Authentication Bypass Using an Alternate Path or Channel vulnerability in Inductiveautomation Ignition 8.1.15
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).
network
low complexity
inductiveautomation CWE-288
critical
9.8
2022-06-01 CVE-2022-31022 Authentication Bypass Using an Alternate Path or Channel vulnerability in Couchbase Bleve
Bleve is a text indexing library for go.
local
low complexity
couchbase CWE-288
5.5
2021-12-27 CVE-2021-33017 Authentication Bypass Using an Alternate Path or Channel vulnerability in Philips products
The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication.
low complexity
philips CWE-288
8.8
2021-12-23 CVE-2021-43985 Authentication Bypass Using an Alternate Path or Channel vulnerability in Myscada Mypro 7/7.0.26/8.20.0
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
network
low complexity
myscada CWE-288
critical
9.8
2021-12-21 CVE-2021-27453 Authentication Bypass Using an Alternate Path or Channel vulnerability in Mesalabs Amegaview
Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application, which may allow an attacker to gain access.
network
low complexity
mesalabs CWE-288
critical
9.8
2021-02-12 CVE-2020-27866 Authentication Bypass Using an Alternate Path or Channel vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers.
low complexity
netgear CWE-288
8.8
2021-02-12 CVE-2020-27865 Authentication Bypass Using an Alternate Path or Channel vulnerability in Dlink Dap-1860 Firmware
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders.
low complexity
dlink CWE-288
8.8
2021-02-12 CVE-2020-27863 Authentication Bypass Using an Alternate Path or Channel vulnerability in Dlink Dsl-2888A Firmware and Dva-2800 Firmware
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A routers.
low complexity
dlink CWE-288
6.5
2020-10-13 CVE-2020-17409 Authentication Bypass Using an Alternate Path or Channel vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6120, R6080, R6260, R6220, R6020, JNR3210, and WNR2020 routers with firmware 1.0.66.
low complexity
netgear CWE-288
6.5