CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,931 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 50 of 99
- CVE-2021-25484MEDIUMCVSS 4.0EG 4.02021-10-06
Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.
- CVE-2021-25490MEDIUMCVSS 6.0EG 6.02021-10-06
A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.
- CVE-2021-25505LOWCVSS 3.3EG 3.32021-11-05
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
- CVE-2021-25506MEDIUMCVSS 4.0EG 4.02021-11-05
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
- CVE-2021-25863HIGHCVSS 8.8EG 8.82021-01-26
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
- CVE-2021-25910HIGHCVSS 8.0EG 8.02021-01-29
Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.
- CVE-2021-26070HIGHCVSS 7.2EG 7.22021-03-22
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected …
- CVE-2021-26073HIGHCVSS 7.7EG 7.72021-04-16
Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassi…
- CVE-2021-26074MEDIUMCVSS 6.5EG 6.52021-04-16
Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian produc…
- CVE-2021-26077HIGHCVSS 8.8EG 8.82021-05-10
Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authenticatio…
- CVE-2021-26088HIGHCVSS 7.1EG 7.12021-07-12
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notificatio…
- CVE-2021-26117HIGHCVSS 7.5EG 7.52021-01-27
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous…
- CVE-2021-26253HIGHCVSS 8.1EG 8.12022-05-06
A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to …
- CVE-2021-26598MEDIUMCVSS 5.3EG 5.32022-03-28
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).
- CVE-2021-26620HIGHCVSS 7.5EG 7.52022-03-25
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentica…
- CVE-2021-26627HIGHCVSS 7.5EG 7.52022-04-19
Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay command and lead to leakage a live image.
- CVE-2021-26637CRITICALCVSS 8.8EG 9.82022-06-23
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
- CVE-2021-26638CRITICALCVSS 7.3EG 9.82022-06-23
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor con…
- CVE-2021-26905MEDIUMCVSS 6.5EG 6.52021-02-08
1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key.
- CVE-2021-27173HIGHCVSS 7.5EG 7.52021-02-10
An issue was discovered on FiberHome HG6245D devices through RP2613. There is a telnet?enable=0&key=calculated(BR0_MAC) backdoor API, without authentication, provided by the HTTP server. This will remove firewall rules and allow an attacke…
- CVE-2021-27215CRITICALCVSS 9.8EG 9.82021-03-03
An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces (Admin, Userweb, Sidechannel) can use different methods to perform the authentication of a user. A s…
- CVE-2021-27444CRITICALCVSS 9.8EG 9.82022-05-16
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate …
- CVE-2021-27451HIGHCVSS 7.3EG 7.32021-12-21
Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device.
- CVE-2021-27522HIGHCVSS 8.8EG 8.82021-04-08
Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the initial letter of the key of a user cookie, the key of the administrator cookie can be obtai…
- CVE-2021-27610CRITICALCVSS 9.8EG 9.82021-06-16
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead t…
- CVE-2021-27651CRITICALCVSS 9.8EG 9.82021-04-29
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
- CVE-2021-27668MEDIUMCVSS 5.3EG 5.32021-08-31
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.
- CVE-2021-27715CRITICALCVSS 9.8EG 9.82023-09-08
An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request.
- CVE-2021-27734CRITICALCVSS 9.8EG 9.82021-05-17
Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.
- CVE-2021-27791MEDIUMCVSS 5.4EG 5.42021-08-12
The function that is used to parse the Authentication header in Brocade Fabric OS Web application service before Brocade Fabric OS v9.0.1a and v8.2.3a fails to properly process a malformed authentication header from the client, resulting i…
- CVE-2021-27794HIGHCVSS 7.8EG 7.82021-08-12
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.
- CVE-2021-27876CRITICALCVSS 8.1EG 9.0⚠ KEV2021-03-01
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability i…
- CVE-2021-27877CRITICALCVSS 8.2EG 9.8⚠ KEV2021-03-01
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet be…
- CVE-2021-27878CRITICALCVSS 8.8EG 9.0⚠ KEV2021-03-01
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability i…
- CVE-2021-27990HIGHCVSS 7.5EG 7.52021-04-14
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.
- CVE-2021-28024CRITICALCVSS 9.8EG 9.82021-11-08
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.
- CVE-2021-28093MEDIUMCVSS 6.5EG 6.52021-07-30
OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.
- CVE-2021-28094MEDIUMCVSS 6.5EG 6.52021-07-30
OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.
- CVE-2021-28095MEDIUMCVSS 4.8EG 4.82021-07-30
OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.
- CVE-2021-28122CRITICALCVSS 9.8EG 9.82021-03-10
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber databa…
- CVE-2021-28124MEDIUMCVSS 5.9EG 5.92021-04-02
A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. Missing server authentication in impacted versions can allow an attacker to Man-in-the-middl…
- CVE-2021-28131HIGHCVSS 7.5EG 7.52021-07-22
Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's se…
- CVE-2021-28148HIGHCVSS 7.5EG 7.52021-03-22
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of re…
- CVE-2021-28152CRITICALCVSS 9.8EG 9.82021-05-06
Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on port 5188 with the default credentials of root:superzxmn.
- CVE-2021-28174MEDIUMCVSS 6.5EG 6.52021-04-08
Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can gain the privileged permissions to access transaction record, and fraudulent trading withou…
- CVE-2021-28235CRITICALCVSS 9.8EG 9.82023-04-04
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
- CVE-2021-28493HIGHCVSS 8.4EG 8.42021-09-09
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metam…
- CVE-2021-28494CRITICALCVSS 9.6EG 9.62021-09-09
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako …
- CVE-2021-28495HIGHCVSS 7.2EG 7.22021-09-09
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Me…
- CVE-2021-28503CRITICALCVSS 7.4EG 9.82022-02-04
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →