CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,925 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 21 of 99
- CVE-2015-4987MEDIUMCVSS 6.5EG 6.52018-03-27
The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified vectors. IBM X-Force ID: 105896.
- CVE-2015-5298MEDIUMCVSS 6.5EG 6.52022-07-07
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modif…
- CVE-2015-6237CRITICALCVSS 9.8EG 9.82017-12-27
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privil…
- CVE-2015-6314CRITICALCVSS 9.8EG 9.82016-01-15
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153.
- CVE-2015-6397HIGHCVSS 8.8EG 8.82016-08-08
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175,…
- CVE-2015-6816CRITICALCVSS 9.8EG 9.82017-08-09
ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
- CVE-2015-6817HIGHCVSS 8.1EG 8.12017-05-23
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
- CVE-2015-6922CRITICALCVSS 9.8EG 9.82020-02-17
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an…
- CVE-2015-6926HIGHCVSS 7.5EG 7.52018-01-19
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token.
- CVE-2015-7224CRITICALCVSS 9.8EG 9.82017-12-21
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.
- CVE-2015-7521HIGHCVSS 8.3EG 8.32016-01-29
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified parti…
- CVE-2015-7746CRITICALCVSS 9.8EG 9.82017-09-01
NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from or (2) modify volumes via vectors related to UTF-8 in the volume language.
- CVE-2015-7755CRITICALCVSS 9.8EG 9.8⚠ KEV2015-12-19
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r…
- CVE-2015-7871CRITICALCVSS 9.8EG 9.82017-08-07
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
- CVE-2015-7882HIGHCVSS 8.1EG 8.12019-07-19
Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.
- CVE-2015-7914HIGHCVSS 8.1EG 8.12016-02-06
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password.
- CVE-2015-7938CRITICALCVSS 9.8EG 9.82016-01-09
Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors.
- CVE-2015-7974HIGHCVSS 7.7EG 7.72016-01-26
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton…
- CVE-2015-8269HIGHCVSS 7.5EG 7.52016-02-04
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number.
- CVE-2015-8308HIGHCVSS 7.8EG 7.82017-08-24
LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.
- CVE-2015-8332HIGHCVSS 8.8EG 8.82017-08-28
Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user …
- CVE-2016-0733CRITICALCVSS 9.8EG 9.82016-04-12
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username.
- CVE-2016-0755HIGHCVSS 7.3EG 7.32016-01-29
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014…
- CVE-2016-0796HIGHCVSS 7.5EG 7.52022-07-28
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacke…
- CVE-2016-0883CRITICALCVSS 9.8EG 9.82016-09-18
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowle…
- CVE-2016-0916CRITICALCVSS 9.8EG 9.82016-06-10
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.
- CVE-2016-1000214MEDIUMCVSS 5.3EG 5.32016-10-25
Ruckus Wireless H500 web management interface authentication bypass
- CVE-2016-10309CRITICALCVSS 9.8EG 9.82017-03-30
In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.
- CVE-2016-10394HIGHCVSS 8.4EG 8.42024-11-26
Initial xbl_sec revision does not have all the debug policy features and critical checks.
- CVE-2016-10434HIGHCVSS 7.5EG 7.52018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 820 and SD 820A, the input to RPMB write response function is a buffer from HLOS that needs to be authenticated (using …
- CVE-2016-10525CRITICALCVSS 9.8EG 9.82018-05-29
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
- CVE-2016-10532CRITICALCVSS 9.8EG 9.82018-05-31
console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2.2.13 and earlier i…
- CVE-2016-10732CRITICALCVSS 9.8EG 9.82018-10-29
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.
- CVE-2016-10826HIGHCVSS 8.8EG 8.82019-08-01
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
- CVE-2016-10831HIGHCVSS 7.2EG 7.22019-08-01
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
- CVE-2016-10832MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
- CVE-2016-10833HIGHCVSS 7.5EG 7.52019-08-01
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
- CVE-2016-10835MEDIUMCVSS 4.3EG 4.32019-08-01
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
- CVE-2016-10836MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
- CVE-2016-10983MEDIUMCVSS 6.5EG 6.52019-09-17
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
- CVE-2016-11041MEDIUMCVSS 4.6EG 4.62020-04-07
An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending an AT command over USB. The Samsung ID is SVE-2015-5301 (June 2016).
- CVE-2016-11042HIGHCVSS 7.5EG 7.52020-04-07
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (June 2016).
- CVE-2016-11057HIGHCVSS 7.5EG 7.52020-04-28
Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 before 2017-01-06, WNR614 before 2017-01-06, WNR618 before 2017-01-06, JWNR2000v5 before 2017-01-06, WNR2020 before 2017-01-06, JWNR2010v5 be…
- CVE-2016-11072MEDIUMCVSS 6.5EG 6.52020-06-19
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
- CVE-2016-11074CRITICALCVSS 9.8EG 9.82020-06-19
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
- CVE-2016-1219CRITICALCVSS 9.8EG 9.82017-04-20
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.
- CVE-2016-1278HIGHCVSS 7.8EG 7.82016-08-05
Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a failed upgrade to 12.1X46, which might allow local users to gain privileges by leveraging…
- CVE-2016-1279CRITICALCVSS 9.8EG 9.82016-09-09
J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 13.3R10, 13.3R9 before 13.3R9-S1, 14.1 before 14.1R7, 14.1X53 before 14.1X53-D35, 14.2 befo…
- CVE-2016-1307MEDIUMCVSS 5.4EG 5.42016-02-07
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.
- CVE-2016-1329CRITICALCVSS 9.8EG 9.82016-03-03
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →