CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,929 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 36 of 99
- CVE-2019-15615MEDIUMCVSS 6.1EG 6.12020-02-04
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
- CVE-2019-15617MEDIUMCVSS 5.4EG 5.42020-02-04
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
- CVE-2019-15620LOWCVSS 2.7EG 2.72020-02-04
Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.
- CVE-2019-15648MEDIUMCVSS 6.5EG 6.52019-08-27
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
- CVE-2019-15796MEDIUMCVSS 4.7EG 4.72020-03-26
Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows downloads from unsigned rep…
- CVE-2019-15803CRITICALCVSS 9.1EG 9.12019-11-14
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts fo…
- CVE-2019-15897CRITICALCVSS 9.6EG 9.62019-12-05
beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exposed to external networks).
- CVE-2019-15987MEDIUMCVSS 5.3EG 5.32019-11-26
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulne…
- CVE-2019-15993MEDIUMCVSS 5.3EG 5.32020-09-23
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to in…
- CVE-2019-16028CRITICALCVSS 9.8EG 9.82020-09-23
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an af…
- CVE-2019-16190CRITICALCVSS 9.8EG 9.82019-09-09
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.
- CVE-2019-16201HIGHCVSS 7.5EG 7.52019-11-26
WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the I…
- CVE-2019-16250HIGHCVSS 7.5EG 7.52019-09-11
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
- CVE-2019-16261CRITICALCVSS 9.1EG 9.12019-09-12
Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's …
- CVE-2019-16286MEDIUMCVSS 6.8EG 6.82019-11-22
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute arbitrary commands.
- CVE-2019-16327CRITICALCVSS 9.8EG 9.82019-12-26
D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.
- CVE-2019-1662CRITICALCVSS 8.2EG 9.12019-02-21
A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insuff…
- CVE-2019-1664HIGHCVSS 7.8EG 7.82019-02-21
A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker…
- CVE-2019-16649CRITICALCVSS 10.0EG 10.02019-09-21
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can u…
- CVE-2019-1666MEDIUMCVSS 5.3EG 5.32019-02-21
A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication controls. An attacker c…
- CVE-2019-16929HIGHCVSS 7.5EG 7.52019-10-08
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
- CVE-2019-17023MEDIUMCVSS 6.5EG 6.52020-01-08
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will …
- CVE-2019-17134CRITICALCVSS 9.1EG 9.12019-10-08
Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration comma…
- CVE-2019-1724HIGHCVSS 8.8EG 8.82019-05-03
A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid user session on an a…
- CVE-2019-17372HIGHCVSS 8.1EG 8.12019-10-09
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin passw…
- CVE-2019-17437HIGHCVSS 7.8EG 7.82019-12-05
An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 …
- CVE-2019-1758MEDIUMCVSS 4.7EG 4.72019-03-28
A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication. The vulnerability is due to how the 802.1x packe…
- CVE-2019-1759MEDIUMCVSS 5.3EG 5.32019-03-28
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet M…
- CVE-2019-17627MEDIUMCVSS 6.5EG 6.52019-10-16
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computation…
- CVE-2019-18246MEDIUMCVSS 4.3EG 4.32020-06-29
BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure.
- CVE-2019-18250CRITICALCVSS 9.8EG 9.82019-11-26
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from t…
- CVE-2019-18252MEDIUMCVSS 4.3EG 4.32020-06-29
BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials used for connecting to the BIOTRONIK Remo…
- CVE-2019-18284CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exposed via this inter…
- CVE-2019-18286MEDIUMCVSS 5.3EG 5.32019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory listings and files containing sensitive information. This vulnerability is independent fr…
- CVE-2019-18287MEDIUMCVSS 5.3EG 5.32019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Application Server exposes directory listings and files containing sensitive information. This vulnerability is independent fr…
- CVE-2019-18312MEDIUMCVSS 5.3EG 5.32019-12-12
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to enumerate running RPC services. Please note that an attacker needs to have netw…
- CVE-2019-18314CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted objects…
- CVE-2019-18315CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets…
- CVE-2019-18317HIGHCVSS 7.5EG 7.52019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafte…
- CVE-2019-18318HIGHCVSS 7.5EG 7.52019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server can cause a Denial-of-Service condition by sending specifically crafted …
- CVE-2019-18319HIGHCVSS 7.5EG 7.52019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafte…
- CVE-2019-18320HIGHCVSS 7.5EG 7.52019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could be able to upload arbitrary files without authentication. Please n…
- CVE-2019-18321CRITICALCVSS 9.1EG 9.12019-12-12
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to read and write arbitrary files on the local file system by sending specifically…
- CVE-2019-18322CRITICALCVSS 9.1EG 9.12019-12-12
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to read and write arbitrary files on the local file system by sending specifically…
- CVE-2019-18332MEDIUMCVSS 5.3EG 5.32019-12-12
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain access to directory listings of the server by sending specifi…
- CVE-2019-18337CRITICALCVSS 9.8EG 9.82019-12-12
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on p…
- CVE-2019-18341MEDIUMCVSS 5.3EG 5.32019-12-12
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) contains an authentication bypass vulnerability. A remote attacker with …
- CVE-2019-18374CRITICALCVSS 9.8EG 9.82019-11-25
Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authenticat…
- CVE-2019-18380MEDIUMCVSS 6.5EG 6.52019-12-09
Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authenticatio…
- CVE-2019-1842MEDIUMCVSS 5.4EG 5.42019-06-05
A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vulnerability is due to…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →