Skip to main content

Threats Tagged 'cwe-603'

View all threats tagged with 'cwe-603'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-603

Threats Tagged 'cwe-603'

Click on any threat for detailed analysis and mitigation recommendations

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.

Join the discussion

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Join the discussion
0

CVE-2026-76945 is a high-severity vulnerability in the Ebyte NE2-D11 firmware where authentication tokens are managed by the client without sufficient server-side validation. This flaw allows an attacker to replay or manipulate authentication tokens to gain unauthorized administrative access.

Join the discussion

CVE-2026-71187 is a critical vulnerability in the Ebyte NA111-M firmware where client-side authentication logic can be reproduced by unauthenticated users. This flaw allows attackers to generate valid authentication requests and bypass authentication, gaining administrative access to the device. The vulnerability has a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently available from the vendor. The affected version explicitly identified is 9013-2-17. There are no known exploits in the wild at this time.

Join the discussion

Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e.g.using a debugger) and log in as any other user or administrator - then it is possible to do every possible change to the repository. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 17.1 and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

Join the discussion

mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 and below.

Join the discussion

The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verification. As a result, possession of the certificate number alone is sufficient for authentication, regardless of the actual presence of the smart card or ownership of the private key.

Join the discussion

CVE-2026-1363 is a critical vulnerability in JNC's IAQS product caused by client-side enforcement of server-side security controls (CWE-603). This flaw allows unauthenticated remote attackers to bypass authentication and gain administrator privileges by manipulating the web front-end. The vulnerability requires no user interaction or privileges and can be exploited remotely over the network. With a CVSS 4.0 score of 9.3, it poses a severe risk to confidentiality, integrity, and availability of affected systems. No patches or known exploits are currently reported. European organizations using IAQS, especially in critical infrastructure or industrial automation sectors, face significant risks of unauthorized control and data compromise. Mitigation requires immediate network-level protections, strict access controls, and vendor engagement for patches. Countries with high adoption of JNC IAQS and strategic industrial targets, such as Germany, France, and the Netherlands, are most likely affected.

Join the discussion

A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management System: through 2.3.9.

Join the discussion

NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Tag: cwe-603
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses