CWE-287— Improper Authentication
4,308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 50 of 87
- CVE-2021-41311HIGHCVSS 7.5EG 7.52021-12-08
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the…
- CVE-2021-41312HIGHCVSS 7.5EG 7.52021-11-03
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Aut…
- CVE-2021-41314HIGHCVSS 8.8EG 8.82021-09-16
Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e…
- CVE-2021-41317CRITICALCVSS 9.8EG 9.82021-09-17
XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
- CVE-2021-41393CRITICALCVSS 9.8EG 9.82021-09-18
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.
- CVE-2021-41418CRITICALCVSS 9.8EG 9.82022-06-15
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.
- CVE-2021-4142MEDIUMCVSS 5.5EG 5.52022-08-24
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
- CVE-2021-41503HIGHCVSS 8.0EG 8.02021-09-24
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malic…
- CVE-2021-41506CRITICALCVSS 9.8EG 9.82022-06-30
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.…
- CVE-2021-41638HIGHCVSS 7.5EG 7.52022-06-24
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.
- CVE-2021-41716CRITICALCVSS 9.8EG 9.82021-12-07
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
- CVE-2021-41753HIGHCVSS 7.5EG 7.52021-09-27
A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in D-Link DIR-X1560, v1.04B04, and DIR-X6060, v1.11B04 allows a remote unauthenticated attacker to disconnect a wireless client via sending specific spoofed SAE authen…
- CVE-2021-41848HIGHCVSS 7.8EG 7.82022-03-11
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoofed software update file that contains an arbitrary shell script and arbitrary ARM binary,…
- CVE-2021-4191MEDIUMCVSS 5.3EG 9.02022-03-28
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through th…
- CVE-2021-4197HIGHCVSS 7.8EG 7.82022-03-23
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged p…
- CVE-2021-41992HIGHCVSS 7.7EG 9.82022-04-30
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
- CVE-2021-41995HIGHCVSS 7.7EG 7.52022-06-30
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
- CVE-2021-4201CRITICALCVSS 9.6EG 9.62022-02-14
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access …
- CVE-2021-42072HIGHCVSS 8.8EG 8.82021-11-08
An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided pr…
- CVE-2021-4230LOWCVSS 3.7EG 7.52022-05-24
A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without proper authentication. …
- CVE-2021-42338CRITICALCVSS 9.8EG 9.82021-11-19
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload…
- CVE-2021-42837CRITICALCVSS 9.8EG 9.82021-11-05
An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username wit…
- CVE-2021-42849MEDIUMCVSS 6.8EG 6.82022-05-18
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
- CVE-2021-42949CRITICALCVSS 9.8EG 9.82022-09-16
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
- CVE-2021-43068MEDIUMCVSS 5.4EG 5.42021-12-09
A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.
- CVE-2021-43116HIGHCVSS 8.8EG 8.82022-07-05
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
- CVE-2021-43136CRITICALCVSS 9.8EG 9.82021-11-10
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
- CVE-2021-4314MEDIUMCVSS 5.3EG 5.32023-01-18
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue…
- CVE-2021-43175HIGHCVSS 7.5EG 7.52021-12-07
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOaut…
- CVE-2021-43183CRITICALCVSS 9.8EG 9.82021-11-09
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
- CVE-2021-43203HIGHCVSS 7.5EG 7.52021-11-09
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
- CVE-2021-43355HIGHCVSS 7.3EG 9.82022-01-21
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users…
- CVE-2021-43394CRITICALCVSS 9.8EG 9.82022-01-24
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.
- CVE-2021-43414HIGHCVSS 7.0EG 7.02021-11-07
An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middle attacks, which can be exploited for local privilege escalation to get full root access.
- CVE-2021-43444HIGHCVSS 7.5EG 7.52023-01-23
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.
- CVE-2021-43445CRITICALCVSS 9.8EG 9.82023-01-23
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.
- CVE-2021-43447HIGHCVSS 7.5EG 7.52023-01-23
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.
- CVE-2021-43483HIGHCVSS 8.0EG 8.02022-04-08
An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.
- CVE-2021-43563HIGHCVSS 8.8EG 8.82021-11-10
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io…
- CVE-2021-43786CRITICALCVSS 9.8EG 9.82021-11-29
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. User…
- CVE-2021-43833HIGHCVSS 8.1EG 8.12021-12-16
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address. Th…
- CVE-2021-43834CRITICALCVSS 9.1EG 9.12021-12-16
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authenticat…
- CVE-2021-43931CRITICALCVSS 9.8EG 9.82021-12-06
The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
- CVE-2021-43935HIGHCVSS 8.1EG 9.82021-12-15
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the applicati…
- CVE-2021-43946MEDIUMCVSS 6.5EG 6.52022-01-05
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. Th…
- CVE-2021-43950MEDIUMCVSS 4.3EG 4.32022-02-15
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source featu…
- CVE-2021-43999HIGHCVSS 8.8EG 8.82022-01-11
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.
- CVE-2021-44032HIGHCVSS 7.5EG 7.52022-03-10
TP-Link Omada SDN Software Controller before 5.0.15 does not check if the authentication method specified in a connection request is allowed. An attacker can bypass the captive portal authentication process by using the downgraded "no auth…
- CVE-2021-44056HIGHCVSS 7.1EG 9.82022-05-05
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in…
- CVE-2021-44057HIGHCVSS 7.1EG 9.82022-05-05
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →