Threats Tagged 'cwe-603'
View all threats tagged with 'cwe-603'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-603'
Click on any threat for detailed analysis and mitigation recommendations
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site. Join the discussion | CVE Database V5 | 09/10/2026, 20:40:28 UTC Added: 09/10/2026, 20:47:29 UTC |
0 Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. Join the discussion | CVE Database V5 | 09/08/2026, 18:32:29 UTC Added: 09/08/2026, 18:54:25 UTC |
0 CVE-2026-76945 is a high-severity vulnerability in the Ebyte NE2-D11 firmware where authentication tokens are managed by the client without sufficient server-side validation. This flaw allows an attacker to replay or manipulate authentication tokens to gain unauthorized administrative access. Join the discussion | CVE Database V5 | 08/27/2026, 21:35:38 UTC Added: 08/28/2026, 11:04:29 UTC |
0 CVE-2026-71187 is a critical vulnerability in the Ebyte NA111-M firmware where client-side authentication logic can be reproduced by unauthenticated users. This flaw allows attackers to generate valid authentication requests and bypass authentication, gaining administrative access to the device. The vulnerability has a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently available from the vendor. The affected version explicitly identified is 9013-2-17. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 08/27/2026, 21:20:04 UTC Added: 08/28/2026, 11:04:25 UTC |
0 Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e.g.using a debugger) and log in as any other user or administrator - then it is possible to do every possible change to the repository. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 17.1 and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. Join the discussion | CVE Database V5 | 05/19/2026, 12:59:29 UTC Added: 05/19/2026, 13:36:54 UTC |
mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 and below. Join the discussion | CVE Database V5 | 04/28/2026, 13:13:21 UTC Added: 04/28/2026, 13:37:43 UTC |
The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verification. As a result, possession of the certificate number alone is sufficient for authentication, regardless of the actual presence of the smart card or ownership of the private key. Join the discussion | CVE Database V5 | 03/02/2026, 11:14:46 UTC Added: 03/02/2026, 11:26:53 UTC |
CVE-2026-1363 is a critical vulnerability in JNC's IAQS product caused by client-side enforcement of server-side security controls (CWE-603). This flaw allows unauthenticated remote attackers to bypass authentication and gain administrator privileges by manipulating the web front-end. The vulnerability requires no user interaction or privileges and can be exploited remotely over the network. With a CVSS 4.0 score of 9.3, it poses a severe risk to confidentiality, integrity, and availability of affected systems. No patches or known exploits are currently reported. European organizations using IAQS, especially in critical infrastructure or industrial automation sectors, face significant risks of unauthorized control and data compromise. Mitigation requires immediate network-level protections, strict access controls, and vendor engagement for patches. Countries with high adoption of JNC IAQS and strategic industrial targets, such as Germany, France, and the Netherlands, are most likely affected. Join the discussion | CVE Database V5 | 01/23/2026, 08:37:32 UTC Added: 01/23/2026, 08:50:57 UTC |
A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management System: through 2.3.9. Join the discussion | CVE Database V5 | 01/02/2026, 21:26:57 UTC Added: 01/02/2026, 21:28:45 UTC |
NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection. Join the discussion | CVE Database V5 | 12/02/2025, 21:07:47 UTC Added: 12/02/2025, 21:16:27 UTC |
Showing 1 to 10 of 14 results