CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,931 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 51 of 99
- CVE-2021-28626HIGHCVSS 3.7EG 7.52021-08-24
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Authorization vulnerability allowing users to create nodes under a location. An unauthenticated attacker could leverage thi…
- CVE-2021-28694MEDIUMCVSS 6.8EG 6.82021-08-27
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which shoul…
- CVE-2021-28958CRITICALCVSS 9.8EG 9.82021-06-25
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
- CVE-2021-29012CRITICALCVSS 9.8EG 9.82021-04-02
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is…
- CVE-2021-29047HIGHCVSS 7.5EG 7.52021-05-16
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA …
- CVE-2021-29065CRITICALCVSS 9.6EG 9.62021-03-23
NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.
- CVE-2021-29066CRITICALCVSS 9.6EG 9.62021-03-23
Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
- CVE-2021-29067CRITICALCVSS 9.6EG 9.62021-03-23
Certain NETGEAR devices are affected by authentication bypass. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.…
- CVE-2021-29149MEDIUMCVSS 6.2EG 6.22021-07-22
A local bypass security restrictions vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8…
- CVE-2021-29151MEDIUMCVSS 4.3EG 4.32021-07-08
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
- CVE-2021-29203CRITICALCVSS 9.8EG 9.82021-05-06
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote a…
- CVE-2021-29396CRITICALCVSS 9.8EG 9.82022-02-04
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.
- CVE-2021-29487HIGHCVSS 7.4EG 7.42021-08-26
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS serv…
- CVE-2021-29655CRITICALCVSS 9.8EG 9.82022-02-18
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.
- CVE-2021-29747HIGHCVSS 7.5EG 7.52021-05-17
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.
- CVE-2021-29758MEDIUMCVSS 4.3EG 4.32021-10-06
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.
- CVE-2021-29765HIGHCVSS 7.5EG 7.52021-08-04
IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service access to the FSP. IBM X-Force ID: 202476.
- CVE-2021-29779MEDIUMCVSS 5.9EG 5.92021-12-01
IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 20…
- CVE-2021-29908CRITICALCVSS 9.8EG 9.82021-10-06
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747.
- CVE-2021-30028HIGHCVSS 7.2EG 7.22022-05-20
SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.
- CVE-2021-30158MEDIUMCVSS 5.3EG 5.32021-04-06
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or…
- CVE-2021-30302HIGHCVSS 7.5EG 7.52021-10-20
Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon…
- CVE-2021-30312HIGHCVSS 7.5EG 7.52021-10-20
Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Sna…
- CVE-2021-30317CRITICALCVSS 9.3EG 9.32022-02-11
Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Sn…
- CVE-2021-3046MEDIUMCVSS 6.8EG 6.82021-08-11
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured t…
- CVE-2021-30605HIGHCVSS 7.8EG 7.82021-09-08
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
- CVE-2021-30648CRITICALCVSS 9.8EG 9.82021-06-30
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configurati…
- CVE-2021-30667MEDIUMCVSS 5.4EG 5.42021-09-08
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force a client to use a less secure authentication mechanism.
- CVE-2021-30668MEDIUMCVSS 4.6EG 4.62021-09-08
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A person with physical access to a Mac may be able to bypass Login Window during a software update.
- CVE-2021-30702MEDIUMCVSS 4.6EG 4.62021-09-08
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A person with physical access to a Mac may be able to bypass Login W…
- CVE-2021-30720MEDIUMCVSS 5.4EG 5.42021-09-08
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary ser…
- CVE-2021-30769MEDIUMCVSS 5.5EG 5.52021-09-08
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
- CVE-2021-30770MEDIUMCVSS 5.5EG 5.52021-09-08
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
- CVE-2021-30867MEDIUMCVSS 5.5EG 5.52021-08-24
The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access photos.
- CVE-2021-31245MEDIUMCVSS 5.9EG 5.92021-05-06
omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.
- CVE-2021-31251CRITICALCVSS 9.8EG 9.82021-06-04
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request …
- CVE-2021-31326CRITICALCVSS 9.8EG 9.82022-03-24
D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.
- CVE-2021-31349CRITICALCVSS 9.8EG 9.82021-10-19
The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to view internal files, change settings, manipulate services and execute arbitrary code. This issue affects all Juniper Net…
- CVE-2021-3145MEDIUMCVSS 6.7EG 6.72021-09-10
In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
- CVE-2021-31520HIGHCVSS 8.1EG 8.12021-05-10
A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently logged-in administrators' session session token in order to gain access to the product's we…
- CVE-2021-3153MEDIUMCVSS 6.5EG 6.52021-03-26
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
- CVE-2021-31559HIGHCVSS 7.5EG 7.52022-05-06
A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPToke…
- CVE-2021-31602HIGHCVSS 5.3EG 8.12021-11-08
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which i…
- CVE-2021-31606HIGHCVSS 7.5EG 7.52021-09-27
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
- CVE-2021-31917CRITICALCVSS 9.8EG 9.82021-09-21
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest th…
- CVE-2021-31924MEDIUMCVSS 6.8EG 6.82021-05-26
Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification …
- CVE-2021-31932CRITICALCVSS 9.8EG 9.82022-02-11
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using UR…
- CVE-2021-32030CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-06
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access …
- CVE-2021-32033MEDIUMCVSS 4.6EG 4.62021-06-16
Protectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in certain situations. The time value used by the device can be set independently from the used seed value for generating time…
- CVE-2021-32071CRITICALCVSS 9.8EG 9.82021-08-13
The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due to improper access control. A successful exploit could allow an attacker to view and modify application data, and cause …
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →