CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,931 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 49 of 99
- CVE-2021-22228MEDIUMCVSS 6.5EG 6.52021-07-06
An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access p…
- CVE-2021-22473HIGHCVSS 7.5EG 7.52021-10-28
There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-22490MEDIUMCVSS 5.3EG 5.32021-10-28
There is a Permission verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect the device performance.
- CVE-2021-22496HIGHCVSS 7.5EG 7.52021-03-25
Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.
- CVE-2021-22497LOWCVSS 3.8EG 3.82021-04-12
Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.
- CVE-2021-22507CRITICALCVSS 9.8EG 9.82021-04-08
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access.
- CVE-2021-22566CRITICALCVSS 9.8EG 9.82022-01-18
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged by an attacker to bypass executability restrictions of kern…
- CVE-2021-22764MEDIUMCVSS 5.3EG 5.32021-06-11
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the devic…
- CVE-2021-22796HIGHCVSS 7.8EG 7.82022-02-11
A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)
- CVE-2021-22858HIGHCVSS 8.8EG 8.82021-02-17
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.
- CVE-2021-22860CRITICALCVSS 9.8EG 9.82021-03-17
EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further …
- CVE-2021-22869CRITICALCVSS 9.8EG 9.82021-09-24
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access contro…
- CVE-2021-22893CRITICALCVSS 10.0EG 10.0⚠ KEV2021-04-23
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated…
- CVE-2021-22943CRITICALCVSS 9.6EG 9.62021-08-31
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vulnerability is fixed…
- CVE-2021-22997HIGHCVSS 7.5EG 7.52021-03-31
On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transport services, and all data used by ElasticSearch for transport is unencrypted. Note: Softw…
- CVE-2021-23008CRITICALCVSS 9.8EG 9.82021-05-10
On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM AD (Active Directory) authentication can be bypassed via a spoofed AS-REP (Kerberos Authe…
- CVE-2021-23147MEDIUMCVSS 6.8EG 6.82021-12-30
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as t…
- CVE-2021-23196CRITICALCVSS 7.3EG 9.82022-01-21
The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.
- CVE-2021-23365MEDIUMCVSS 4.8EG 4.82021-04-26
The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity …
- CVE-2021-23847CRITICALCVSS 9.8EG 9.82021-06-09
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CP…
- CVE-2021-23857CRITICALCVSS 10.0EG 10.02021-10-04
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
- CVE-2021-23923HIGHCVSS 8.1EG 8.12021-04-01
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
- CVE-2021-24017MEDIUMCVSS 5.4EG 5.42021-09-30
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler.
- CVE-2021-24148CRITICALCVSS 9.8EG 9.82021-03-18
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.
- CVE-2021-24175CRITICALCVSS 9.8EG 9.82021-04-05
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing…
- CVE-2021-24359MEDIUMCVSS 5.3EG 5.32021-06-14
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registere…
- CVE-2021-24527CRITICALCVSS 9.8EG 9.82021-08-16
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is ch…
- CVE-2021-24647HIGHCVSS 8.1EG 8.12021-11-08
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as …
- CVE-2021-24649CRITICALCVSS 9.8EG 9.82022-11-21
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an at…
- CVE-2021-24881HIGHCVSS 7.5EG 7.52023-01-23
The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (…
- CVE-2021-25036HIGHCVSS 8.8EG 8.82022-01-17
The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they sh…
- CVE-2021-25147HIGHCVSS 8.1EG 8.12021-04-28
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-25281CRITICALCVSS 9.8EG 9.82021-02-27
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
- CVE-2021-25315CRITICALCVSS 9.8EG 9.82021-03-03
CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: …
- CVE-2021-25341MEDIUMCVSS 4.0EG 4.02021-03-04
Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.
- CVE-2021-25342MEDIUMCVSS 4.0EG 4.02021-03-04
Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.
- CVE-2021-25343MEDIUMCVSS 4.0EG 4.02021-03-04
Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provid…
- CVE-2021-25347MEDIUMCVSS 5.3EG 5.32021-03-04
Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is executed.
- CVE-2021-25368LOWCVSS 3.3EG 3.32021-03-25
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.
- CVE-2021-25377LOWCVSS 3.3EG 3.32021-04-09
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.
- CVE-2021-25389LOWCVSS 2.3EG 2.32021-06-11
Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.
- CVE-2021-25424HIGHCVSS 8.8EG 8.82021-06-11
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.
- CVE-2021-25430MEDIUMCVSS 4.3EG 4.32021-07-08
Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
- CVE-2021-25442HIGHCVSS 7.5EG 7.52021-07-08
Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.
- CVE-2021-25445MEDIUMCVSS 5.3EG 5.32021-08-05
Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.
- CVE-2021-25446MEDIUMCVSS 5.3EG 5.32021-08-05
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
- CVE-2021-25447MEDIUMCVSS 5.3EG 5.32021-08-05
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
- CVE-2021-25448MEDIUMCVSS 5.3EG 5.32021-08-05
Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.
- CVE-2021-25451LOWCVSS 3.3EG 3.32021-09-09
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
- CVE-2021-25466MEDIUMCVSS 6.5EG 6.52021-09-09
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →