This weakness has been deprecated because it covered redundant concepts already described in CWE-287.
Volume of CVEs assigned to CWE-592 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10933CRITICAL A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, r | Oct 17, 2018 | 9.1 | 90 | NO | YES |
CVE-2026-43512CRITICAL DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 | May 12, 2026 | 9.8 | 40 | NO | NO |
CVE-2016-8371HIGH The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled. | Apr 5, 2018 | 7.3 | 35 | NO | YES |
CVE-2018-14643CRITICAL An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machi | Sep 21, 2018 | 9.8 | 33 | NO | NO |
CVE-2014-5432CRITICAL Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A r | Mar 26, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-3899CRITICAL It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as ship | Apr 22, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-14910CRITICAL A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case | Dec 5, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-1085CRITICAL openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the value | Jun 15, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-2684CRITICAL Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the a | Feb 22, 2017 | 9.0 | 29 | NO | NO |
CVE-2018-10847HIGH prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same acro | Jul 30, 2018 | 8.8 | 28 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.