CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,924 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 17 of 99
- CVE-2013-4874MEDIUMCVSS v2 6.2EG 6.22013-07-18
The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by connecting a crafted HDMI cable and using a sys session to modify the ramboot environment variable.
- CVE-2013-4875MEDIUMCVSS v2 6.2EG 6.22013-07-18
The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and obtain a login prompt by connecting a crafted HDMI cable and sending a SysReq interrupt.
- CVE-2013-4877LOWCVSS v2 2.6EG 2.62013-07-18
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the netw…
- CVE-2013-4958MEDIUMCVSS v2 6.9EG 6.92013-08-20
Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation.
- CVE-2013-4965MEDIUMCVSS v2 5.0EG 5.02013-10-25
Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force attack.
- CVE-2013-4966MEDIUMCVSS v2 6.4EG 6.42014-03-09
The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.
- CVE-2013-4976CRITICALCVSS 9.8EG 9.82019-12-27
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
- CVE-2013-4982CRITICALCVSS 9.8EG 9.82019-12-27
AVTECH AVN801 DVR has a security bypass via the administration login captcha
- CVE-2013-5009HIGHCVSS v2 7.4EG 7.42014-01-10
The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly perform authentication, which allows remot…
- CVE-2013-5038MEDIUMCVSS v2 5.8EG 5.82013-12-30
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.
- CVE-2013-5112MEDIUMCVSS 4.6EG 4.62020-01-31
Evernote before 5.5.1 has insecure PIN storage
- CVE-2013-5114MEDIUMCVSS 6.1EG 6.12020-01-31
LastPass prior to 2.5.1 allows secure wipe bypass.
- CVE-2013-5116HIGHCVSS 7.1EG 7.12020-01-31
Evernote prior to 5.5.1 has insecure password change
- CVE-2013-5119MEDIUMCVSS v2 6.8EG 6.82013-09-23
Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_AUTH_TOKEN token.
- CVE-2013-5122CRITICALCVSS 9.8EG 9.82020-01-07
Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access
- CVE-2013-5123MEDIUMCVSS 5.9EG 5.92019-11-05
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
- CVE-2013-5163MEDIUMCVSS v2 6.6EG 6.62013-10-04
Directory Services in Apple Mac OS X before 10.8.5 Supplemental Update allows local users to bypass password-based authentication and modify arbitrary Directory Services records via unspecified vectors.
- CVE-2013-5200HIGHCVSS v2 7.5EG 7.52013-09-25
The (1) REST and (2) memcache interfaces in the Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 do not require authentication, which allows remote attackers to obtain sensitive informati…
- CVE-2013-5413MEDIUMCVSS v2 4.3EG 4.32013-12-21
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
- CVE-2013-5426MEDIUMCVSS v2 4.9EG 4.92013-12-19
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 al…
- CVE-2013-5429LOWCVSS v2 2.1EG 2.12014-01-21
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens,…
- CVE-2013-5497MEDIUMCVSS v2 4.3EG 4.32013-09-19
The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted m…
- CVE-2013-5510MEDIUMCVSS v2 4.3EG 4.32013-10-13
The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x befo…
- CVE-2013-5511HIGHCVSS v2 10.0EG 10.02013-10-13
The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12…
- CVE-2013-5531MEDIUMCVSS v2 5.0EG 5.02013-10-25
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.
- CVE-2013-5582HIGHCVSS 7.8EG 7.82020-02-11
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.
- CVE-2013-5944HIGHCVSS v2 10.0EG 10.02013-10-03
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform admini…
- CVE-2013-6006MEDIUMCVSS v2 5.8EG 5.82013-12-28
Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.
- CVE-2013-6012HIGHCVSS v2 8.5EG 8.52013-10-28
Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configuration validation errors during the config commit phase of the boot-up sequence, which allows…
- CVE-2013-6031MEDIUMCVSS v2 4.3EG 4.32014-03-11
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to change passwords and settings, or obtain sensitive information, via a direct request to (1) api/wlan/sec…
- CVE-2013-6035HIGHCVSS v2 10.0EG 10.02014-02-04
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for s…
- CVE-2013-6117HIGHCVSS v2 7.5EG 7.52014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP po…
- CVE-2013-6171MEDIUMCVSS v2 5.8EG 5.82013-12-09
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted …
- CVE-2013-6347MEDIUMCVSS v2 6.8EG 6.82013-11-02
Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.
- CVE-2013-6360HIGHCVSS 7.5EG 7.52020-02-13
TRENDnet TS-S402 has a backdoor to enable TELNET.
- CVE-2013-6439HIGHCVSS v2 9.3EG 9.32013-12-23
Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.
- CVE-2013-6470MEDIUMCVSS v2 5.0EG 5.02014-06-02
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote attackers to gain …
- CVE-2013-6634MEDIUMCVSS v2 6.8EG 6.82013-12-07
The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fix…
- CVE-2013-6643HIGHCVSS v2 7.5EG 7.52014-01-16
The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync …
- CVE-2013-6765HIGHCVSS v2 7.5EG 7.52014-05-19
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLI…
- CVE-2013-6766HIGHCVSS v2 7.5EG 7.52014-05-19
OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP commands via a crafted OAP request for version information, which causes the state to be set …
- CVE-2013-6788HIGHCVSS v2 7.5EG 7.52014-05-30
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force atta…
- CVE-2013-6806MEDIUMCVSS v2 6.8EG 6.82014-05-19
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends…
- CVE-2013-6828MEDIUMCVSS v2 6.4EG 6.42013-11-20
admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it parameter.
- CVE-2013-6859HIGHCVSS v2 8.5EG 8.52013-11-23
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 does not properly perform authorization, which allows remote authenticated users to gain privileges via un…
- CVE-2013-6890MEDIUMCVSS v2 5.0EG 5.02013-12-23
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.
- CVE-2013-6920HIGHCVSS v2 10.0EG 10.02013-12-07
Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.
- CVE-2013-6979MEDIUMCVSS v2 5.4EG 5.42013-12-23
The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.…
- CVE-2013-7051HIGHCVSS 8.8EG 8.82020-02-04
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
- CVE-2013-7093MEDIUMCVSS v2 5.0EG 5.02013-12-13
SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vectors.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →