CWE-287— Improper Authentication
4,302 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 25 of 87
- CVE-2018-13804HIGHCVSS 8.1EG 8.12018-12-13
A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UA Discrete Manufacturing (Versions < V1.2), SIMATIC IT UA Discrete Manufacturing (Versions V1.2), SI…
- CVE-2018-13816CRITICALCVSS 10.0EG 10.02018-12-12
A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although configured. Successful exploitation requires an attacker to be able to send packets to port 1…
- CVE-2018-13821CRITICALCVSS 9.8EG 9.82018-08-30
A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including file reading/writing.
- CVE-2018-13927HIGHCVSS 7.8EG 7.82019-07-22
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connecti…
- CVE-2018-13990HIGHCVSS 8.6EG 9.82019-05-06
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.
- CVE-2018-14008MEDIUMCVSS 6.5EG 6.52019-08-15
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
- CVE-2018-14078CRITICALCVSS 9.8EG 9.82018-08-20
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username with password "admin" after a successful a…
- CVE-2018-14080HIGHCVSS 7.5EG 7.52018-10-09
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file.
- CVE-2018-1418HIGHCVSS 8.8EG 8.82018-04-26
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
- CVE-2018-14345HIGHCVSS 7.5EG 7.52018-07-17
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical sessi…
- CVE-2018-1443MEDIUMCVSS 5.9EG 5.92018-03-08
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated…
- CVE-2018-14637MEDIUMCVSS 6.1EG 6.12018-11-30
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
- CVE-2018-14643CRITICALCVSS 9.8EG 9.82018-09-21
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly pr…
- CVE-2018-14705CRITICALCVSS 9.8EG 9.82020-02-24
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only …
- CVE-2018-14708CRITICALCVSS 9.8EG 9.82018-12-03
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
- CVE-2018-14709CRITICALCVSS 9.8EG 9.82018-12-03
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation.
- CVE-2018-14781MEDIUMCVSS 5.3EG 5.32018-08-13
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless tran…
- CVE-2018-14782HIGHCVSS 7.5EG 7.52018-08-10
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and profiles without authenticating the user.
- CVE-2018-14786CRITICALCVSS 9.4EG 9.42018-08-23
Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper authentication vulnerability where the software does not pe…
- CVE-2018-14805CRITICALCVSS 9.8EG 9.82018-08-29
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vuln…
- CVE-2018-14826CRITICALCVSS 9.8EG 9.82018-10-02
Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a specially crafted URL. This could allow for remote code execution.
- CVE-2018-14868MEDIUMCVSS 6.5EG 6.52019-06-28
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
- CVE-2018-15152CRITICALCVSS 9.1EG 9.12018-08-15
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.p…
- CVE-2018-15371MEDIUMCVSS 6.7EG 6.72018-10-05
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability ex…
- CVE-2018-1539MEDIUMCVSS 5.4EG 6.52018-09-25
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.
- CVE-2018-15478HIGHCVSS 8.1EG 8.12018-08-30
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The proces…
- CVE-2018-15479MEDIUMCVSS 6.5EG 6.52018-08-30
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. Devices di…
- CVE-2018-15485CRITICALCVSS 9.1EG 9.12018-09-07
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or authorization, aka KONE-03.
- CVE-2018-15542MEDIUMCVSS 6.4EG 6.42018-10-09
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attack…
- CVE-2018-15543MEDIUMCVSS 6.8EG 6.82018-10-09
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthentic…
- CVE-2018-15556CRITICALCVSS 9.8EG 9.82019-06-27
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.
- CVE-2018-15598HIGHCVSS 7.5EG 7.52018-08-21
Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
- CVE-2018-15667HIGHCVSS 7.5EG 7.52018-08-21
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" command in the URL scheme allows an external application to send arbitrary emails from an active account without authen…
- CVE-2018-15721CRITICALCVSS 9.8EG 9.82018-12-20
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to gain access to the local API.
- CVE-2018-15727CRITICALCVSS 9.8EG 9.82018-08-29
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
- CVE-2018-15751CRITICALCVSS 9.8EG 9.82018-10-24
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
- CVE-2018-15819HIGHCVSS 7.5EG 7.52020-03-02
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
- CVE-2018-16160HIGHCVSS 7.8EG 7.82018-11-15
SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Windows PC.
- CVE-2018-16219HIGHCVSS 8.8EG 8.82019-04-25
A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same network as the device) to change the admin password without authentication via a POST request.
- CVE-2018-16286CRITICALCVSS 9.8EG 9.82018-09-14
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
- CVE-2018-1638MEDIUMCVSS 5.9EG 8.12018-07-31
IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.
- CVE-2018-16464MEDIUMCVSS 5.7EG 5.72018-10-30
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.
- CVE-2018-16465MEDIUMCVSS 5.3EG 5.32018-10-30
Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load.
- CVE-2018-16467MEDIUMCVSS 5.3EG 5.32018-10-30
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
- CVE-2018-16496MEDIUMCVSS 5.3EG 5.32021-05-26
In Versa Director, the un-authentication request found.
- CVE-2018-16590CRITICALCVSS 9.8EG 9.82018-09-06
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
- CVE-2018-16668MEDIUMCVSS 5.3EG 5.32018-09-18
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.
- CVE-2018-16670MEDIUMCVSS 5.3EG 5.32018-09-18
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
- CVE-2018-1668MEDIUMCVSS 5.3EG 7.52019-01-29
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM…
- CVE-2018-1672MEDIUMCVSS 5.0EG 6.32018-10-01
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →