CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,924 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 18 of 99
- CVE-2013-7183HIGHCVSS v2 7.8EG 7.82014-02-04
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a default_reboot action or (2) reset all configuration values via a factory_default action.
- CVE-2013-7239MEDIUMCVSS v2 4.8EG 4.82014-01-13
memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending another request with incorrect SASL credentials.
- CVE-2013-7282HIGHCVSS v2 10.0EG 10.02014-01-10
The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows remote attackers to bypass authentication via a "Cookie: :language=en" HTTP header.
- CVE-2013-7292LOWCVSS v2 3.5EG 3.52014-01-13
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password…
- CVE-2013-7302MEDIUMCVSS v2 6.8EG 6.82014-04-29
Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by levera…
- CVE-2013-7322MEDIUMCVSS v2 4.9EG 4.92014-03-09
usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP an…
- CVE-2013-7366MEDIUMCVSS v2 5.0EG 5.02014-04-10
The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors related to failed authentications.
- CVE-2013-7465CRITICALCVSS 9.8EG 9.82018-10-05
Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary code by uploading PHP scripts.
- CVE-2014-0015MEDIUMCVSS v2 4.0EG 4.02014-02-02
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
- CVE-2014-0074HIGHCVSS v2 7.5EG 7.52014-10-06
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
- CVE-2014-0090MEDIUMCVSS v2 6.8EG 6.82014-05-08
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
- CVE-2014-0097HIGHCVSS 7.3EG 7.32017-05-25
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty passwor…
- CVE-2014-0121CRITICALCVSS 9.8EG 9.82017-12-29
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
- CVE-2014-0132MEDIUMCVSS v2 6.5EG 6.52014-03-18
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
- CVE-2014-0138MEDIUMCVSS v2 6.4EG 6.42014-04-15
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attacker…
- CVE-2014-0166MEDIUMCVSS v2 6.4EG 6.42014-04-10
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain acc…
- CVE-2014-0188HIGHCVSS v2 7.5EG 7.52014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate…
- CVE-2014-0348LOWCVSS v2 3.5EG 3.52014-04-15
The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows remote attackers to …
- CVE-2014-0353MEDIUMCVSS v2 6.1EG 6.12014-04-15
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to bypass authentication by using %2F sequences in place of / (slash) characters.
- CVE-2014-0357MEDIUMCVSS v2 5.0EG 5.02014-04-15
Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application.
- CVE-2014-0635HIGHCVSS v2 7.5EG 7.52014-04-01
Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.
- CVE-2014-0643HIGHCVSS v2 7.6EG 7.62014-05-16
EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge o…
- CVE-2014-0674MEDIUMCVSS v2 6.8EG 6.82014-01-24
Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging netwo…
- CVE-2014-0722MEDIUMCVSS v2 5.0EG 5.02014-02-13
The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified use of this applica…
- CVE-2014-0725MEDIUMCVSS v2 5.0EG 5.02014-02-13
Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified access to a "file storage location," aka Bug ID CSCum05337.
- CVE-2014-0732MEDIUMCVSS v2 5.0EG 5.02014-02-20
The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files vi…
- CVE-2014-0733MEDIUMCVSS v2 5.0EG 5.02014-02-20
The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct req…
- CVE-2014-0737MEDIUMCVSS v2 4.3EG 4.32014-02-22
The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795.
- CVE-2014-0738MEDIUMCVSS v2 4.3EG 4.32014-02-22
The Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID …
- CVE-2014-0739MEDIUMCVSS v2 4.3EG 4.32014-02-22
Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via …
- CVE-2014-0743MEDIUMCVSS v2 5.0EG 5.02014-02-27
The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, …
- CVE-2014-0760HIGHCVSS v2 9.3EG 9.32014-04-25
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attacker to execute arbi…
- CVE-2014-0769HIGHCVSS v2 9.3EG 9.32014-04-25
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the con…
- CVE-2014-0927HIGHCVSS 8.1EG 8.12018-04-20
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID:…
- CVE-2014-0973HIGHCVSS v2 7.2EG 7.22014-08-25
The image_verify function in platform/msm_shared/image_verify.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not check whether a …
- CVE-2014-10067MEDIUMCVSS 5.9EG 5.92018-05-29
paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a request using the simul…
- CVE-2014-10389CRITICALCVSS 9.8EG 9.82019-08-22
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
- CVE-2014-125060CRITICALCVSS 7.3EG 9.82023-01-07
A vulnerability, which was classified as critical, was found in holdennb CollabCal. Affected is the function handleGet of the file calenderServer.cpp. The manipulation leads to improper authentication. It is possible to launch the attack r…
- CVE-2014-1295MEDIUMCVSS v2 6.8EG 6.82014-04-23
Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which all…
- CVE-2014-1517MEDIUMCVSS v2 4.0EG 4.02014-04-20
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive informa…
- CVE-2014-1682MEDIUMCVSS v2 4.0EG 4.02014-05-08
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
- CVE-2014-1867HIGHCVSS 7.8EG 7.82019-12-13
suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution
- CVE-2014-1911HIGHCVSS v2 7.8EG 7.82014-03-06
The Foscam FI8910W camera with firmware before 11.37.2.55 allows remote attackers to obtain sensitive video and image data via a blank username and password.
- CVE-2014-1982HIGHCVSS v2 10.0EG 10.02014-03-31
The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a dir…
- CVE-2014-1984MEDIUMCVSS v2 6.8EG 6.82014-04-19
Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors.
- CVE-2014-2005MEDIUMCVSS 6.8EG 6.82014-06-25
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop a…
- CVE-2014-2047MEDIUMCVSS v2 6.8EG 6.82014-03-14
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.
- CVE-2014-2075HIGHCVSS v2 10.0EG 10.02014-02-27
TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authentication requirements, which allows remote attackers to execute arbitrary commands via unspecified vectors.
- CVE-2014-2128MEDIUMCVSS v2 5.0EG 5.02014-04-10
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to by…
- CVE-2014-2181MEDIUMCVSS v2 6.8EG 6.82014-05-07
Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted URL to the HTTP server, as demonstrated by reading the running configuration, aka Bug ID CSCun78551.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →