CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,929 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 30 of 99
- CVE-2018-12169HIGHCVSS 7.6EG 7.62018-09-21
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic er…
- CVE-2018-12192MEDIUMCVSS 6.8EG 6.82019-03-14
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authe…
- CVE-2018-12242CRITICALCVSS 9.8EG 9.82018-09-19
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain acce…
- CVE-2018-12271MEDIUMCVSS 6.4EG 6.42018-06-13
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAcce…
- CVE-2018-1237CRITICALCVSS 9.8EG 9.82018-03-27
Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This component is deployed on every server in the ScaleIO cluster and is used for central mana…
- CVE-2018-12399MEDIUMCVSS 4.3EG 4.32019-02-28
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise…
- CVE-2018-12445LOWCVSS 3.1EG 3.12018-06-20
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticati…
- CVE-2018-12446LOWCVSS 3.6EG 3.62018-06-20
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker …
- CVE-2018-12455HIGHCVSS 8.1EG 8.12018-10-10
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by using "admin:" as the name of a cookie.
- CVE-2018-12472CRITICALCVSS 7.3EG 9.12018-10-04
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
- CVE-2018-12551HIGHCVSS 8.1EG 8.12019-03-27
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a usern…
- CVE-2018-12575CRITICALCVSS 9.8EG 9.82018-07-02
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.
- CVE-2018-12613CRITICALCVSS 8.8EG 9.02018-06-21
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpM…
- CVE-2018-12666CRITICALCVSS 9.8EG 9.82018-10-19
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting…
- CVE-2018-12667CRITICALCVSS 9.8EG 9.82018-10-19
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) is affected by an improper authentication vulnerability that allows requests to be made to back-end CGI scripts without a valid session. This v…
- CVE-2018-12804CRITICALCVSS 9.8EG 9.82018-07-20
Adobe Connect versions 9.7.5 and earlier have an Authentication Bypass vulnerability. Successful exploitation could lead to session hijacking.
- CVE-2018-1286MEDIUMCVSS 6.5EG 6.52018-02-28
In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.
- CVE-2018-12984CRITICALCVSS 9.8EG 9.82018-06-29
Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.
- CVE-2018-13060MEDIUMCVSS 6.5EG 6.52020-03-16
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
- CVE-2018-1312CRITICALCVSS 9.8EG 9.82018-03-26
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authent…
- CVE-2018-1317HIGHCVSS 8.8EG 8.82019-04-23
In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentication.
- CVE-2018-1343CRITICALCVSS 9.8EG 9.82018-03-06
PAM exposure enabling unauthenticated access to remote host
- CVE-2018-13434MEDIUMCVSS 6.3EG 6.32018-08-16
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSec…
- CVE-2018-13435HIGHCVSS 7.0EG 7.02018-08-16
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indi…
- CVE-2018-13446HIGHCVSS 7.0EG 7.02018-08-16
An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker co…
- CVE-2018-13789HIGHCVSS 7.5EG 7.52018-10-10
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
- CVE-2018-13804HIGHCVSS 8.1EG 8.12018-12-13
A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UA Discrete Manufacturing (Versions < V1.2), SIMATIC IT UA Discrete Manufacturing (Versions V1.2), SI…
- CVE-2018-13816CRITICALCVSS 10.0EG 10.02018-12-12
A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although configured. Successful exploitation requires an attacker to be able to send packets to port 1…
- CVE-2018-13821CRITICALCVSS 9.8EG 9.82018-08-30
A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including file reading/writing.
- CVE-2018-13927HIGHCVSS 7.8EG 7.82019-07-22
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connecti…
- CVE-2018-13990CRITICALCVSS 8.6EG 9.82019-05-06
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.
- CVE-2018-14008MEDIUMCVSS 6.5EG 6.52019-08-15
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
- CVE-2018-14078CRITICALCVSS 9.8EG 9.82018-08-20
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username with password "admin" after a successful a…
- CVE-2018-14080HIGHCVSS 7.5EG 7.52018-10-09
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file.
- CVE-2018-1418HIGHCVSS 8.8EG 8.92018-04-26
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
- CVE-2018-14345HIGHCVSS 7.5EG 7.52018-07-17
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical sessi…
- CVE-2018-1443MEDIUMCVSS 5.9EG 5.92018-03-08
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated…
- CVE-2018-14637MEDIUMCVSS 6.1EG 6.12018-11-30
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
- CVE-2018-14643CRITICALCVSS 9.8EG 9.82018-09-21
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly pr…
- CVE-2018-14705CRITICALCVSS 9.8EG 9.82020-02-24
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only …
- CVE-2018-14708CRITICALCVSS 9.8EG 9.82018-12-03
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
- CVE-2018-14709CRITICALCVSS 9.8EG 9.82018-12-03
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation.
- CVE-2018-14781MEDIUMCVSS 5.3EG 5.32018-08-13
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless tran…
- CVE-2018-14782HIGHCVSS 7.5EG 7.52018-08-10
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and profiles without authenticating the user.
- CVE-2018-14786CRITICALCVSS 9.4EG 9.42018-08-23
Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper authentication vulnerability where the software does not pe…
- CVE-2018-14805CRITICALCVSS 9.8EG 9.82018-08-29
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vuln…
- CVE-2018-14826CRITICALCVSS 9.8EG 9.82018-10-02
Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a specially crafted URL. This could allow for remote code execution.
- CVE-2018-14868MEDIUMCVSS 6.5EG 6.52019-06-28
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
- CVE-2018-15152CRITICALCVSS 9.1EG 9.12018-08-15
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.p…
- CVE-2018-15371MEDIUMCVSS 6.7EG 6.72018-10-05
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability ex…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →