CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,929 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 39 of 99
- CVE-2019-7392CRITICALCVSS 9.1EG 9.12019-02-26
An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration.
- CVE-2019-7579HIGHCVSS 7.5EG 7.52019-06-17
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.187766/dynamic/js/setup.js.localized file on the router's webserver, allowing for an attac…
- CVE-2019-7666HIGHCVSS 8.8EG 8.82019-07-01
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the pas…
- CVE-2019-8108MEDIUMCVSS 6.5EG 6.52019-11-05
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate session validation setting for a storefront that leads to inse…
- CVE-2019-8443HIGHCVSS 8.1EG 8.12019-05-22
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpg…
- CVE-2019-8533HIGHCVSS 7.8EG 7.82019-12-18
A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave 10.14.4. A Mac may not lock when disconnecting from an external monitor.
- CVE-2019-8634HIGHCVSS 8.8EG 8.82019-12-18
An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged in to another user’s account.
- CVE-2019-8704MEDIUMCVSS 5.5EG 5.52019-12-18
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.
- CVE-2019-8760MEDIUMCVSS 6.8EG 6.82019-12-18
This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.
- CVE-2019-8804MEDIUMCVSS 5.7EG 5.72019-12-18
An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.
- CVE-2019-8978HIGHCVSS 8.1EG 8.12019-05-14
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in conjunction with SSO …
- CVE-2019-8990HIGHCVSS 8.1EG 8.12019-04-09
The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even when authentication is…
- CVE-2019-9124CRITICALCVSS 9.8EG 9.82019-02-25
An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.
- CVE-2019-9496HIGHCVSS 7.5EG 7.52019-04-17
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerabl…
- CVE-2019-9497HIGHCVSS 8.1EG 8.12019-04-17
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing t…
- CVE-2019-9498HIGHCVSS 8.1EG 8.12019-04-17
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use inv…
- CVE-2019-9499HIGHCVSS 8.1EG 8.12019-04-17
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete auth…
- CVE-2019-9531CRITICALCVSS 9.8EG 9.82019-10-10
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT)…
- CVE-2019-9564CRITICALCVSS 7.5EG 9.82022-03-30
A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8…
- CVE-2019-9629CRITICALCVSS 9.8EG 9.82019-07-08
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
- CVE-2020-0460HIGHCVSS 7.5EG 7.52020-12-14
In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. U…
- CVE-2020-0688CRITICALCVSS 8.8EG 9.0⚠ KEV2020-02-11
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
- CVE-2020-0837MEDIUMCVSS 5.0EG 5.02020-09-11
<p>An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but no…
- CVE-2020-0943MEDIUMCVSS 4.6EG 4.62020-04-15
An authentication bypass vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications generated by work profiles.This could allow an unauthenticated attacker to view notif…
- CVE-2020-10048MEDIUMCVSS 5.5EG 5.52021-02-09
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus b…
- CVE-2020-10123MEDIUMCVSS 5.3EG 5.32020-08-21
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components …
- CVE-2020-10135MEDIUMCVSS 5.4EG 5.42020-05-19
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthent…
- CVE-2020-10148CRITICALCVSS 9.8EG 9.8⚠ KEV2020-12-29
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may res…
- CVE-2020-10254MEDIUMCVSS 5.9EG 5.92021-02-19
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview.
- CVE-2020-10278MEDIUMCVSS 4.6EG 4.62020-06-24
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.
- CVE-2020-10288CRITICALCVSS 9.8EG 9.82020-07-15
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.
- CVE-2020-10539CRITICALCVSS 9.8EG 9.82021-02-05
An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user password's MD5 hash stored in the database. It is also compared …
- CVE-2020-10570MEDIUMCVSS 6.1EG 6.12020-03-24
The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended restrictions on message reading and message replying. This might be interpreted as a bypass of the…
- CVE-2020-10594CRITICALCVSS 9.1EG 9.12020-03-15
An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible …
- CVE-2020-10669HIGHCVSS 7.5EG 7.52020-03-19
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the docume…
- CVE-2020-10709HIGHCVSS 7.1EG 7.12021-05-27
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The…
- CVE-2020-10754MEDIUMCVSS 4.3EG 4.32020-06-08
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication doe…
- CVE-2020-10816HIGHCVSS 7.5EG 7.52020-10-08
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
- CVE-2020-10833HIGHCVSS 7.5EG 7.52020-03-24
An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notifications. The Samsung ID is SVE-2019-16532 (March 2020).
- CVE-2020-10846MEDIUMCVSS 5.5EG 5.52020-03-24
An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019…
- CVE-2020-10847MEDIUMCVSS 6.8EG 6.82020-03-24
An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SVE-2019-16614 (February 2020).
- CVE-2020-10888CRITICALCVSS 9.8EG 9.82020-03-25
This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists …
- CVE-2020-10916HIGHCVSS 8.0EG 8.02020-05-07
This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-ver1-0-1-P1[20191213-rel60361] Wi-Fi extenders. Although authentication is required to exp…
- CVE-2020-10918HIGHCVSS 7.5EG 7.52020-07-23
This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exis…
- CVE-2020-10965HIGHCVSS 8.1EG 8.12020-03-25
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerability only exists when the default admin account is not disabled…
- CVE-2020-11012CRITICALCVSS 9.3EG 9.32020-04-23
MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an admin access key, it is possible to perform admin API operations i.e. creating new service accounts for existing access…
- CVE-2020-11020HIGHCVSS 8.5EG 8.52020-04-29
Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system. The vulnerability allows any client to bypass checks put in place by server-side extens…
- CVE-2020-11101CRITICALCVSS 9.8EG 9.82022-12-26
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.
- CVE-2020-11264CRITICALCVSS 9.1EG 9.12021-09-08
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivi…
- CVE-2020-11301CRITICALCVSS 9.1EG 9.12021-09-08
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdr…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →