CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,929 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 41 of 99
- CVE-2020-15055HIGHCVSS 8.8EG 8.82020-08-07
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
- CVE-2020-15059HIGHCVSS 8.8EG 8.82020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
- CVE-2020-15063HIGHCVSS 8.8EG 8.82020-08-07
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
- CVE-2020-15077MEDIUMCVSS 5.3EG 5.32021-06-04
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further inform…
- CVE-2020-15078HIGHCVSS 7.5EG 7.52021-04-26
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
- CVE-2020-15136MEDIUMCVSS 6.5EG 6.52020-08-06
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records f…
- CVE-2020-15149CRITICALCVSS 9.9EG 9.92020-08-20
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. Th…
- CVE-2020-15164CRITICALCVSS 10.0EG 10.02020-08-28
in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whitespace and trimmed by MediaWiki. This af…
- CVE-2020-15222HIGHCVSS 8.1EG 8.12020-09-24
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is not checked. When using client authentication method "priva…
- CVE-2020-15240HIGHCVSS 7.4EG 7.42020-10-21
omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Improper validation of the JWT token signature can allow an attacker to bypass authentication…
- CVE-2020-15243CRITICALCVSS 9.1EG 9.12020-10-08
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1…
- CVE-2020-15269HIGHCVSS 7.4EG 7.42020-10-20
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linke…
- CVE-2020-15482HIGHCVSS 7.8EG 7.82020-08-26
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over t…
- CVE-2020-15506CRITICALCVSS 9.8EG 9.82020-07-07
An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to bypass authentication mechanisms v…
- CVE-2020-15601HIGHCVSS 8.1EG 8.12020-08-27
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authenticatio…
- CVE-2020-15605HIGHCVSS 8.1EG 8.12020-08-27
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager auth…
- CVE-2020-15787CRITICALCVSS 9.8EG 9.82020-09-09
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a set number of chara…
- CVE-2020-15802MEDIUMCVSS 5.9EG 5.92020-09-11
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated user to establish a bonding with one tra…
- CVE-2020-15835CRITICALCVSS 9.8EG 9.82021-02-01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary wit…
- CVE-2020-15838HIGHCVSS 8.8EG 8.82020-10-09
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
- CVE-2020-15896HIGHCVSS 7.5EG 7.52020-07-22
An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessible by any unauthorized user, e.g., logout.php and login.php. This occurs because of check…
- CVE-2020-15921CRITICALCVSS 9.8EG 9.82020-07-24
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.
- CVE-2020-15949HIGHCVSS 7.5EG 7.52020-11-05
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
- CVE-2020-16088CRITICALCVSS 9.8EG 9.82020-07-28
iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.
- CVE-2020-16098CRITICALCVSS 9.8EG 9.82020-09-15
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions of 8.10 prior to v8.10.1211(MR5), versions of 8.00 prior to …
- CVE-2020-16102HIGHCVSS 7.1EG 7.12020-12-14
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart. This issue affects:…
- CVE-2020-16169CRITICALCVSS 9.8EG 9.82020-08-07
Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it automatically answer the attacker's calls, g…
- CVE-2020-1618MEDIUMCVSS 6.3EG 6.32020-04-08
On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password. This issue might only occur in certain scenarios: • At the first reboot a…
- CVE-2020-16222HIGHCVSS 8.8EG 8.82020-09-11
In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.
- CVE-2020-16239MEDIUMCVSS 4.9EG 4.92020-08-21
When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficiently proves the claim is correct.
- CVE-2020-16251HIGHCVSS 8.2EG 8.22020-08-26
HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.
- CVE-2020-1637HIGHCVSS 7.2EG 7.22020-04-08
A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy. This issue might occur when the IP address range configured…
- CVE-2020-1675HIGHCVSS 8.3EG 8.32020-10-16
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could allow a malicious network-based user to access unauthorized …
- CVE-2020-16839HIGHCVSS 7.5EG 7.52021-07-30
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.
- CVE-2020-17020LOWCVSS 3.3EG 3.32020-11-11
Microsoft Word Security Feature Bypass Vulnerability
- CVE-2020-17040MEDIUMCVSS 6.5EG 6.52020-11-11
Windows Hyper-V Security Feature Bypass Vulnerability
- CVE-2020-1718HIGHCVSS 7.1EG 7.12020-05-12
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
- CVE-2020-17466CRITICALCVSS 9.8EG 9.82020-08-11
Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.
- CVE-2020-17510CRITICALCVSS 9.8EG 9.82020-11-05
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
- CVE-2020-17523CRITICALCVSS 9.8EG 9.82021-02-03
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
- CVE-2020-1778MEDIUMCVSS 4.1EG 4.12020-11-23
When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.
- CVE-2020-1786MEDIUMCVSS 4.6EG 4.62020-01-09
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacke…
- CVE-2020-1787MEDIUMCVSS 6.6EG 6.62020-01-09
HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could allow the attacker who gains the privilege…
- CVE-2020-1788MEDIUMCVSS 5.5EG 5.52020-01-21
Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An atta…
- CVE-2020-1789MEDIUMCVSS 6.8EG 6.82020-02-18
Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentication vulnerability. The software does not require a strong credential when the user trying to do certain operations. S…
- CVE-2020-1793MEDIUMCVSS 4.6EG 4.62020-03-20
There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application wh…
- CVE-2020-1794MEDIUMCVSS 4.6EG 4.62020-03-20
There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application wh…
- CVE-2020-1798MEDIUMCVSS 4.6EG 4.62020-05-29
HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. A logic error occurs when handling NFC work, an attacker should establish a NFC connection to the target phone, and t…
- CVE-2020-1801MEDIUMCVSS 5.5EG 5.52020-04-10
There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the caller's identity in certain share scenario, successful exploit could cause information d…
- CVE-2020-1803MEDIUMCVSS 5.3EG 5.32020-04-20
Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3P3),versions earlier than 10.0.0.180(C432E10R3P4) have an information disclosure vulnerability. The device does not suf…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →