CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,931 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 52 of 99
- CVE-2021-32541MEDIUMCVSS 5.3EG 5.32021-05-28
The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attackers can send a large number of valid usernames, and force those logged-in account to log …
- CVE-2021-32543MEDIUMCVSS 6.5EG 6.52021-05-28
The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity.
- CVE-2021-32579HIGHCVSS 7.8EG 7.82021-08-05
Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service API.
- CVE-2021-32637CRITICALCVSS 10.0EG 10.02021-05-28
Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_request_module with Authelia, it allows a malicious individual who crafts a malformed HTTP request to bypass the authentic…
- CVE-2021-32646MEDIUMCVSS 5.3EG 5.32021-05-28
Roomer is a discord bot cog (extension) which provides automatic voice channel generation as well as private voice and text channels. A vulnerability has been discovered allowing discord users to get the ``manage channel`` permissions in a…
- CVE-2021-32648CRITICALCVSS 8.2EG 9.0⚠ KEV2021-08-26
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. Th…
- CVE-2021-32691HIGHCVSS 8.8EG 8.82021-06-16
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday…
- CVE-2021-32693MEDIUMCVSS 6.8EG 6.82021-06-17
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines …
- CVE-2021-32726HIGHCVSS 7.1EG 7.12021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous …
- CVE-2021-32738MEDIUMCVSS 6.5EG 6.52021-07-02
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the cha…
- CVE-2021-32753HIGHCVSS 8.3EG 8.32021-07-09
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is co…
- CVE-2021-32794MEDIUMCVSS 6.8EG 6.82021-07-26
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /Api/ASF` ASF API endpoint responsible for updating global ASF config incorrectly removed `…
- CVE-2021-3282HIGHCVSS 7.5EG 7.52021-02-01
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
- CVE-2021-32951MEDIUMCVSS 5.3EG 5.32021-10-27
WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all t…
- CVE-2021-32967CRITICALCVSS 9.8EG 9.82021-08-30
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.
- CVE-2021-3297HIGHCVSS 7.8EG 7.82021-01-26
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
- CVE-2021-32980CRITICALCVSS 9.8EG 9.82022-04-04
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections. An attacker can connect to the PLC while an existing connection is already active.
- CVE-2021-32984CRITICALCVSS 9.8EG 9.82022-04-04
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized use…
- CVE-2021-32986CRITICALCVSS 9.8EG 9.82022-04-04
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subseq…
- CVE-2021-33044CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-15
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
- CVE-2021-33045CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-15
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
- CVE-2021-33046CRITICALCVSS 9.8EG 9.82022-01-13
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.
- CVE-2021-33076MEDIUMCVSS 5.3EG 6.82022-09-20
Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
- CVE-2021-33083MEDIUMCVSS 4.4EG 4.42022-05-12
Improper authentication in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow an privileged user to potentially enable information disclosure via local access.
- CVE-2021-33087MEDIUMCVSS 5.5EG 5.52021-11-17
Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2021-33159HIGHCVSS 7.4EG 7.42022-11-11
Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2021-33210MEDIUMCVSS 4.3EG 4.32021-11-03
An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information without authentication by reading the response of APIs from a kiosk view of a plant.
- CVE-2021-3325CRITICALCVSS 9.8EG 9.82021-01-27
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without consider…
- CVE-2021-3332MEDIUMCVSS 5.3EG 5.32021-03-01
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
- CVE-2021-3339MEDIUMCVSS 4.3EG 4.32021-02-19
ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.
- CVE-2021-33539HIGHCVSS 7.2EG 7.22021-06-25
In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traf…
- CVE-2021-33700HIGHCVSS 7.8EG 7.82021-09-15
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information w…
- CVE-2021-33766CRITICALCVSS 7.3EG 9.0⚠ KEV2021-07-14
Microsoft Exchange Server Information Disclosure Vulnerability
- CVE-2021-33831MEDIUMCVSS 6.5EG 6.52021-09-07
api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection chains by creating 500 random users within 2500 seconds.
- CVE-2021-33842HIGHCVSS 8.8EG 8.82021-06-09
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be w…
- CVE-2021-33843MEDIUMCVSS 5.3EG 5.32022-01-21
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.
- CVE-2021-33895HIGHCVSS 8.1EG 8.12021-06-25
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verifying the Password r…
- CVE-2021-34166CRITICALCVSS 9.8EG 9.82021-07-30
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.
- CVE-2021-3424MEDIUMCVSS 5.3EG 5.32021-06-01
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.
- CVE-2021-34523CRITICALCVSS 9.0EG 9.8⚠ KEV2021-07-14
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2021-34546MEDIUMCVSS 6.8EG 6.82021-06-10
An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and ex…
- CVE-2021-34578CRITICALCVSS 9.8EG 9.82021-08-31
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.
- CVE-2021-3458MEDIUMCVSS 6.1EG 6.12021-08-17
The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.
- CVE-2021-34675HIGHCVSS 7.5EG 7.52021-07-19
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
- CVE-2021-34676HIGHCVSS 7.5EG 7.52021-07-19
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
- CVE-2021-34690CRITICALCVSS 9.8EG 9.82021-07-15
iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980.
- CVE-2021-34746CRITICALCVSS 9.8EG 9.82021-09-02
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an aff…
- CVE-2021-34785HIGHCVSS 6.5EG 7.22021-09-09
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
- CVE-2021-34786MEDIUMCVSS 6.5EG 6.52021-09-09
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
- CVE-2021-34865HIGHCVSS 8.8EG 8.82022-01-25
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_htt…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →