CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,929 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 35 of 99
- CVE-2019-11018CRITICALCVSS 9.8EG 9.82019-04-08
application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change.
- CVE-2019-11064CRITICALCVSS 9.8EG 9.82019-08-29
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text vi…
- CVE-2019-11081CRITICALCVSS 9.8EG 9.82019-04-24
A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative access to the application server.
- CVE-2019-11170HIGHCVSS 7.8EG 7.82019-11-14
Authentication bypass in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via local access.
- CVE-2019-11187CRITICALCVSS 9.8EG 9.82019-08-15
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.
- CVE-2019-11202CRITICALCVSS 9.8EG 9.82019-07-30
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known pass…
- CVE-2019-11232CRITICALCVSS 9.8EG 9.82019-06-19
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.
- CVE-2019-11234CRITICALCVSS 9.8EG 9.82019-04-22
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
- CVE-2019-11272HIGHCVSS 7.3EG 7.32019-06-26
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder…
- CVE-2019-11488HIGHCVSS 8.1EG 8.12019-04-25
Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allows Unauthorized Attackers to READ/WRITE Customer or Administrator data via a persistent HTTP GET Request Hash Link Repla…
- CVE-2019-11576CRITICALCVSS 9.8EG 9.82019-04-28
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.
- CVE-2019-11733CRITICALCVSS 9.8EG 9.82019-09-27
When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' …
- CVE-2019-12254CRITICALCVSS 9.8EG 9.82022-05-06
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the …
- CVE-2019-12300CRITICALCVSS 9.8EG 9.82019-05-23
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the vic…
- CVE-2019-12394CRITICALCVSS 9.8EG 9.82019-12-02
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.
- CVE-2019-12395MEDIUMCVSS 5.3EG 5.32019-05-28
In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting.
- CVE-2019-12405CRITICALCVSS 9.8EG 9.82019-09-09
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to imprope…
- CVE-2019-12440CRITICALCVSS 9.8EG 9.82019-05-29
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
- CVE-2019-12530CRITICALCVSS 9.8EG 9.82019-06-02
Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.
- CVE-2019-12564CRITICALCVSS 9.8EG 9.82019-06-03
In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames.
- CVE-2019-12643CRITICALCVSS 10.0EG 10.02019-08-28
A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper …
- CVE-2019-12664HIGHCVSS 7.5EG 7.52019-09-25
A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN c…
- CVE-2019-12768CRITICALCVSS 9.8EG 9.82020-12-30
An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass authentication via forceful browsing.
- CVE-2019-12845MEDIUMCVSS 5.3EG 5.32019-07-03
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
- CVE-2019-13188CRITICALCVSS 9.8EG 9.82019-09-05
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
- CVE-2019-13190MEDIUMCVSS 5.3EG 5.32019-09-05
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
- CVE-2019-13294CRITICALCVSS 9.8EG 9.82019-07-04
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.
- CVE-2019-13336CRITICALCVSS 9.8EG 9.82019-10-08
The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arbitrary values. NOTE…
- CVE-2019-13361MEDIUMCVSS 6.5EG 6.52019-09-05
Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.
- CVE-2019-13372CRITICALCVSS 9.8EG 9.82019-07-06
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty …
- CVE-2019-13423HIGHCVSS 8.8EG 8.82019-08-23
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all of the following conditions a-c are true…
- CVE-2019-13526HIGHCVSS 8.8EG 8.82019-08-30
Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker to remotely execute arbitrary code.
- CVE-2019-13531MEDIUMCVSS 4.8EG 4.82019-11-08
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security me…
- CVE-2019-14238MEDIUMCVSS 6.6EG 6.62019-09-24
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug probe via the Instruction Tightly Coupled Memory (ITCM) bus.
- CVE-2019-14239MEDIUMCVSS 6.6EG 6.62019-09-24
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the…
- CVE-2019-14432HIGHCVSS 8.8EG 8.82019-08-07
Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods in which a user is r…
- CVE-2019-14480CRITICALCVSS 9.8EG 9.82020-12-16
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
- CVE-2019-14510MEDIUMCVSS 6.7EG 6.72019-10-11
An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdminxxxxxxxxx (e.g., FSAdmin123456789) on the server that hosts the LAN Cache and all client…
- CVE-2019-14553MEDIUMCVSS 4.9EG 4.92020-11-23
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
- CVE-2019-14598MEDIUMCVSS 6.7EG 6.72020-02-13
Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege…
- CVE-2019-14705HIGHCVSS 7.2EG 7.22019-08-06
An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 because any valid cookie can be used to make requests as an admin.
- CVE-2019-14856MEDIUMCVSS 6.5EG 6.52019-11-26
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
- CVE-2019-14870MEDIUMCVSS 5.4EG 5.42019-12-10
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained deleg…
- CVE-2019-14880CRITICALCVSS 9.1EG 9.12020-03-31
A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the ri…
- CVE-2019-14909HIGHCVSS 8.3EG 8.32019-12-04
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
- CVE-2019-14910CRITICALCVSS 9.8EG 9.82019-12-05
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has e…
- CVE-2019-14985CRITICALCVSS 9.8EG 9.82019-08-13
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.
- CVE-2019-15046HIGHCVSS 7.5EG 7.52019-08-14
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
- CVE-2019-15299HIGHCVSS 8.8EG 8.82020-02-24
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass…
- CVE-2019-15585CRITICALCVSS 9.8EG 9.82020-01-28
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's a…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →