CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,929 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 34 of 99
- CVE-2018-7358CRITICALCVSS 6.5EG 9.02018-11-14
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.
- CVE-2018-7532CRITICALCVSS 9.8EG 9.82018-03-22
Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.
- CVE-2018-7572MEDIUMCVSS 6.8EG 6.82018-09-12
Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privileges of Pulse Secure C…
- CVE-2018-7745HIGHCVSS 7.5EG 7.52018-03-07
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/installation/createuserinfo requests, resulting in account creation.
- CVE-2018-7749CRITICALCVSS 9.8EG 9.82018-03-12
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.
- CVE-2018-7750CRITICALCVSS 9.8EG 9.82018-03-13
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentic…
- CVE-2018-7760CRITICALCVSS 9.8EG 9.82018-04-18
An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization.
- CVE-2018-7791CRITICALCVSS 9.8EG 9.82018-08-29
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the origina…
- CVE-2018-7847CRITICALCVSS 9.8EG 9.82019-05-22
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration se…
- CVE-2018-7910MEDIUMCVSS 6.8EG 6.82018-11-13
Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.127(C432), 8.0.0.128(C432), 8.0.0.137(C432), BLA-L29C 8.0.0.129(C432), 8.0.0.137(C432) have an authentication bypass vu…
- CVE-2018-7940MEDIUMCVSS 6.2EG 6.22018-05-10
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and b…
- CVE-2018-7941HIGHCVSS 8.8EG 8.82018-05-10
Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload a…
- CVE-2018-7943HIGHCVSS 8.8EG 8.82018-06-05
There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerab…
- CVE-2018-7947LOWCVSS 3.9EG 3.92018-07-31
Huawei mobile phones with versions earlier before Emily-AL00A 8.1.0.153(C00) have an authentication bypass vulnerability. An attacker could trick the user to connect to a malicious device. In the debug mode, the malicious software in the d…
- CVE-2018-7949HIGHCVSS 8.8EG 8.82018-06-01
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authenticat…
- CVE-2018-7958HIGHCVSS 7.4EG 7.42018-11-27
There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to hijack the connection from a client when the user signs up to log in by TLS.…
- CVE-2018-7989MEDIUMCVSS 4.6EG 4.62018-10-17
Huawei Mate 10 pro smartphones with the versions before BLA-AL00B 8.1.0.326(C00) have an improper authentication vulnerability. App Lock is a function to prevent unauthorized use of apps on smartphones, an attacker could directly change th…
- CVE-2018-8096CRITICALCVSS 9.8EG 9.82018-03-14
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","Value":false' in an api/settings/setting-isauthenticationenabled PUT request.
- CVE-2018-8171HIGHCVSS 7.5EG 7.52018-07-11
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET …
- CVE-2018-8710CRITICALCVSS 9.8EG 9.82018-03-14
A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJA…
- CVE-2018-8715HIGHCVSS 8.1EG 8.12018-03-15
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login type…
- CVE-2018-8859CRITICALCVSS 9.8EG 9.82018-07-24
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file b…
- CVE-2018-8862LOWCVSS 3.1EG 3.12018-05-25
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability caused by specially crafted malicious radio transmissions may allow an attacker to remotely trigger…
- CVE-2018-8898CRITICALCVSS 9.8EG 9.82018-05-23
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modificati…
- CVE-2018-8902MEDIUMCVSS 6.5EG 6.52018-06-29
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access …
- CVE-2018-9024MEDIUMCVSS 5.3EG 5.32018-06-18
An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.
- CVE-2018-9032CRITICALCVSS 9.8EG 9.82018-03-27
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal b…
- CVE-2018-9080MEDIUMCVSS 5.9EG 5.92018-09-28
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allo…
- CVE-2018-9105HIGHCVSS 8.8EG 8.82018-03-27
NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemented XPC service. This XPC service is responsible for receiving and processing new OpenVPN co…
- CVE-2018-9148CRITICALCVSS 9.8EG 9.82018-03-30
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CV…
- CVE-2018-9232HIGHCVSS 7.8EG 7.82018-05-01
Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and use it as an update.
- CVE-2018-9248CRITICALCVSS 9.8EG 9.82018-04-04
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
- CVE-2018-9249CRITICALCVSS 9.8EG 9.82018-04-04
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
- CVE-2019-0282MEDIUMCVSS 5.3EG 5.32019-04-10
Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like release information, Jav…
- CVE-2019-0543CRITICALCVSS 7.8EG 9.0⚠ KEV2019-01-08
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows S…
- CVE-2019-0622MEDIUMCVSS 4.6EG 4.62019-01-08
An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.
- CVE-2019-10150MEDIUMCVSS 5.9EG 5.92019-06-12
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alte…
- CVE-2019-10157MEDIUMCVSS 4.7EG 4.72019-06-12
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token se…
- CVE-2019-1020018HIGHCVSS 7.3EG 7.32019-07-29
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
- CVE-2019-10273MEDIUMCVSS 4.3EG 4.32019-04-04
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to …
- CVE-2019-10562HIGHCVSS 7.8EG 7.82020-09-08
u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdr…
- CVE-2019-10643CRITICALCVSS 9.8EG 9.82019-04-17
Contao 4.7 allows Use of a Key Past its Expiration Date.
- CVE-2019-10661CRITICALCVSS 9.8EG 9.82019-03-30
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
- CVE-2019-10689MEDIUMCVSS 6.5EG 6.52019-06-24
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, r…
- CVE-2019-10884HIGHCVSS 8.8EG 8.82019-04-05
Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for usersite.example.com.…
- CVE-2019-10911HIGHCVSS 7.5EG 7.52019-05-16
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login…
- CVE-2019-10964HIGHCVSS 7.1EG 7.12019-06-28
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not pro…
- CVE-2019-10966MEDIUMCVSS 5.3EG 5.32019-07-10
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device c…
- CVE-2019-10998MEDIUMCVSS 6.8EG 6.82019-06-18
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD car…
- CVE-2019-11015MEDIUMCVSS 6.8EG 6.82019-04-18
A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscreen based authentication via the Wallpaper Carousel application to obtain sensitive Clipboard data and the user's stored…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →