CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,924 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 16 of 99
- CVE-2013-2820HIGHCVSS v2 10.0EG 10.02014-01-15
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.
- CVE-2013-2944MEDIUMCVSS v2 4.9EG 4.92013-05-02
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
- CVE-2013-2954MEDIUMCVSS v2 5.0EG 5.02013-05-27
The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the number of incorrect authentication attempts, which makes it easier for remote attackers to ob…
- CVE-2013-2993MEDIUMCVSS v2 5.8EG 5.82013-08-01
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session…
- CVE-2013-3039MEDIUMCVSS v2 5.4EG 5.42013-09-12
IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.
- CVE-2013-3046MEDIUMCVSS v2 4.3EG 4.32014-05-26
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not send the HSTS Strict-Transport-Security header, which makes it easier for man-in-the-middle attackers to hijack sessions or obtain sensitive informatio…
- CVE-2013-3071CRITICALCVSS 9.8EG 9.82020-01-28
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
- CVE-2013-3072CRITICALCVSS 9.8EG 9.82019-11-14
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a pa…
- CVE-2013-3085CRITICALCVSS 9.8EG 9.82019-12-26
An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
- CVE-2013-3088CRITICALCVSS 9.8EG 9.82019-12-26
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
- CVE-2013-3091CRITICALCVSS 9.8EG 9.82020-02-07
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
- CVE-2013-3092HIGHCVSS v2 8.3EG 8.32014-09-29
The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation of the HTTP Authorization header.
- CVE-2013-3096MEDIUMCVSS 5.9EG 5.92020-02-07
D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.
- CVE-2013-3215CRITICALCVSS 9.8EG 9.82020-01-29
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
- CVE-2013-3268HIGHCVSS v2 10.0EG 10.02013-04-24
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
- CVE-2013-3316CRITICALCVSS 9.8EG 9.82020-01-29
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
- CVE-2013-3317CRITICALCVSS 9.8EG 9.82020-01-29
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
- CVE-2013-3367CRITICALCVSS 9.8EG 9.82019-11-13
Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
- CVE-2013-3417MEDIUMCVSS v2 5.0EG 5.02013-09-30
The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262.
- CVE-2013-3430HIGHCVSS v2 9.0EG 9.02013-07-25
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID…
- CVE-2013-3431HIGHCVSS v2 7.8EG 7.82013-07-25
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors,…
- CVE-2013-3466HIGHCVSS v2 9.3EG 9.32013-08-29
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitra…
- CVE-2013-3473HIGHCVSS v2 7.8EG 7.82013-09-20
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and password…
- CVE-2013-3581HIGHCVSS v2 7.1EG 7.12013-07-02
ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to obtain sensitive information via an Ajax (1) wmxState or (2) netState request.
- CVE-2013-3586HIGHCVSS v2 7.6EG 7.62013-08-28
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.
- CVE-2013-3610MEDIUMCVSS v2 6.1EG 6.12013-10-05
qis/QIS_finish.htm on the ASUS RT-N10E router with firmware before 2.0.0.25 does not require authentication, which allows remote attackers to discover the administrator password via a direct request.
- CVE-2013-3613HIGHCVSS v2 7.8EG 7.82013-09-17
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.
- CVE-2013-3656MEDIUMCVSS v2 5.8EG 5.82013-07-20
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.
- CVE-2013-3659LOWCVSS v2 3.3EG 3.32013-08-09
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverag…
- CVE-2013-3977MEDIUMCVSS v2 4.3EG 4.32014-05-26
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names.
- CVE-2013-4001MEDIUMCVSS v2 4.3EG 4.32013-12-14
Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.
- CVE-2013-4061MEDIUMCVSS v2 4.0EG 4.02013-09-09
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP redirect via unspecif…
- CVE-2013-4178MEDIUMCVSS v2 5.0EG 5.02014-05-29
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).
- CVE-2013-4304HIGHCVSS v2 7.5EG 7.52014-01-26
The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows…
- CVE-2013-4454CRITICALCVSS 9.1EG 9.12020-02-18
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities
- CVE-2013-4462CRITICALCVSS 9.1EG 9.12020-01-27
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability
- CVE-2013-4471MEDIUMCVSS v2 5.5EG 5.52014-05-14
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the auth…
- CVE-2013-4552HIGHCVSS v2 7.5EG 7.52014-05-13
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via the user name (uid) in a cookie.
- CVE-2013-4580MEDIUMCVSS v2 6.8EG 6.82014-05-12
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.
- CVE-2013-4593HIGHCVSS 7.5EG 7.52019-12-11
RubyGem omniauth-facebook has an access token security vulnerability
- CVE-2013-4594MEDIUMCVSS v2 4.3EG 4.32014-10-25
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.
- CVE-2013-4621CRITICALCVSS 9.8EG 9.82019-12-27
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
- CVE-2013-4731HIGHCVSS v2 9.3EG 9.32013-06-30
ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to execute arbitrary commands via shell metacharacters in the pip parameter in an Ajax tag_ipPing request, a different vuln…
- CVE-2013-4772HIGHCVSS v2 9.3EG 9.32014-05-12
D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a direct request when an authorized session is active.
- CVE-2013-4782HIGHCVSS v2 10.0EG 10.02013-07-08
The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
- CVE-2013-4783HIGHCVSS v2 10.0EG 10.02013-07-08
The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher ze…
- CVE-2013-4784HIGHCVSS v2 10.0EG 10.02013-07-08
The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
- CVE-2013-4793HIGHCVSS v2 7.5EG 7.52014-12-27
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a cra…
- CVE-2013-4824HIGHCVSS v2 7.5EG 7.52013-10-13
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.
- CVE-2013-4863HIGHCVSS 8.8EG 8.82020-01-28
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users …
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →