CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,924 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 20 of 99
- CVE-2014-6379HIGHCVSS v2 7.5EG 7.52014-10-14
Juniper Junos 11.4 before R12, 12.1 before R10, 12.1X44 before D35, 12.1X45 before D25, 12.1X46 before D20, 12.1X47 before D10, 12.2 before R8, 12.2X50 before D70, 12.3 before R6, 13.1 before R4-S3, 13.1X49 before D55, 13.1X50 before D30, …
- CVE-2014-6387MEDIUMCVSS v2 5.0EG 5.02014-10-22
gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.
- CVE-2014-6435HIGHCVSS 7.5EG 7.52018-01-12
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request.
- CVE-2014-6436CRITICALCVSS 9.8EG 9.82018-01-12
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by l…
- CVE-2014-6632HIGHCVSS v2 7.5EG 7.52014-10-08
Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions via vectors involving LDAP authentication.
- CVE-2014-7807MEDIUMCVSS v2 5.0EG 5.02014-12-10
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
- CVE-2014-7857CRITICALCVSS 9.8EG 9.82017-08-25
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administr…
- CVE-2014-7858CRITICALCVSS 9.8EG 9.82017-08-25
The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username cookie parameter to an arbitrary string.
- CVE-2014-7860MEDIUMCVSS 5.3EG 5.32017-08-25
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebo…
- CVE-2014-7879HIGHCVSS v2 8.5EG 8.52014-12-10
HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication, and consequently execute arbitrary code, via unspecified vectors.
- CVE-2014-8006MEDIUMCVSS v2 4.3EG 4.32014-12-17
The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422.
- CVE-2014-8033MEDIUMCVSS v2 5.0EG 5.02015-01-09
The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.
- CVE-2014-8180MEDIUMCVSS 5.5EG 5.52017-06-06
MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.
- CVE-2014-8329HIGHCVSS v2 10.0EG 10.02014-10-20
Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direc…
- CVE-2014-8347HIGHCVSS 7.8EG 7.82020-02-11
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.
- CVE-2014-8424HIGHCVSS v2 7.8EG 7.82014-11-28
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
- CVE-2014-8472MEDIUMCVSS v2 6.8EG 6.82014-11-04
CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
- CVE-2014-8522HIGHCVSS v2 7.5EG 7.52014-10-29
The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers to obtain access.
- CVE-2014-8650CRITICALCVSS 9.8EG 9.82019-12-15
python-requests-Kerberos through 0.5 does not handle mutual authentication
- CVE-2014-8763MEDIUMCVSS v2 5.0EG 5.02014-10-22
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated …
- CVE-2014-8764MEDIUMCVSS v2 5.0EG 5.02014-10-22
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.
- CVE-2014-8896MEDIUMCVSS v2 4.0EG 4.02014-12-22
The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4…
- CVE-2014-9043MEDIUMCVSS v2 5.0EG 5.02015-02-04
The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to bypass authentication via a null byte in the password and a valid user name, which tri…
- CVE-2014-9045MEDIUMCVSS v2 5.0EG 5.02015-02-04
The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requirements via a crafted password.
- CVE-2014-9184MEDIUMCVSS v2 5.0EG 5.02014-12-02
ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi.
- CVE-2014-9217MEDIUMCVSS v2 5.0EG 5.02014-12-08
Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.
- CVE-2014-9278MEDIUMCVSS v2 4.0EG 4.02014-12-06
The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which migh…
- CVE-2014-9320CRITICALCVSS 9.8EG 9.82021-08-09
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.
- CVE-2014-9578MEDIUMCVSS v2 5.0EG 5.02015-01-08
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.
- CVE-2014-9611CRITICALCVSS 9.8EG 9.82017-09-19
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/index.php.
- CVE-2014-9618CRITICALCVSS 9.8EG 9.82017-09-19
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.
- CVE-2014-9624HIGHCVSS 7.5EG 7.52017-09-12
CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
- CVE-2014-9753CRITICALCVSS 9.8EG 9.82020-02-11
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.
- CVE-2014-9952HIGHCVSS 7.8EG 7.82017-06-06
In the Secure File System in all Android releases from CAF using the Linux kernel, a capture-replay vulnerability could potentially exist.
- CVE-2015-0102HIGHCVSS 8.1EG 8.12020-02-05
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
- CVE-2015-0198HIGHCVSS v2 10.0EG 10.02015-03-24
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspe…
- CVE-2015-0607MEDIUMCVSS v2 4.3EG 4.32015-03-06
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt…
- CVE-2015-0653HIGHCVSS v2 10.0EG 10.02015-03-13
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows rem…
- CVE-2015-0670MEDIUMCVSS v2 6.4EG 6.42015-03-21
The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML re…
- CVE-2015-10083CRITICALCVSS 6.3EG 9.82023-02-21
A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper aut…
- CVE-2015-1187CRITICALCVSS 9.8EG 9.8⚠ KEV2017-09-21
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
- CVE-2015-1401CRITICALCVSS 9.8EG 9.82017-08-28
Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
- CVE-2015-1778CRITICALCVSS 9.8EG 9.82017-06-27
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
- CVE-2015-2033HIGHCVSS v2 10.0EG 10.02015-02-20
Anyterm Daemon in Infoblox Network Automation NetMRI before NETMRI-23483 allows remote attackers to execute arbitrary commands with root privileges via a crafted terminal/anyterm-module request.
- CVE-2015-2047LOWCVSS v2 2.6EG 2.62015-02-23
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to …
- CVE-2015-2800HIGHCVSS 7.5EG 7.52017-06-08
The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH012 and S7700, S9300, and S9700 with software before V200R001SPH015 allows remote attackers to cause a denial of servic…
- CVE-2015-2880HIGHCVSS 8.8EG 8.82017-04-10
TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.
- CVE-2015-3206HIGHCVSS 8.1EG 8.12017-08-25
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in…
- CVE-2015-3442CRITICALCVSS 9.8EG 9.82017-09-07
Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API call.
- CVE-2015-4464CRITICALCVSS 9.8EG 9.82017-08-18
Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →