CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,931 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 53 of 99
- CVE-2021-34977HIGHCVSS 8.8EG 8.82022-01-13
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists wi…
- CVE-2021-34993CRITICALCVSS 9.8EG 9.82022-01-13
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService…
- CVE-2021-35029CRITICALCVSS 9.8EG 9.82021-07-02
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote …
- CVE-2021-35033HIGHCVSS 7.8EG 7.82021-11-23
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles t…
- CVE-2021-35094HIGHCVSS 7.8EG 7.82022-06-14
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-3519MEDIUMCVSS 6.4EG 6.42021-11-12
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
- CVE-2021-35252HIGHCVSS 7.5EG 7.52022-12-16
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
- CVE-2021-35296CRITICALCVSS 9.8EG 9.82021-10-04
An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path.
- CVE-2021-35324CRITICALCVSS 9.8EG 9.82021-08-05
A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.
- CVE-2021-3547HIGHCVSS 7.4EG 7.42021-07-12
OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client c…
- CVE-2021-35528HIGHCVSS 7.2EG 7.22021-11-17
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. …
- CVE-2021-35530HIGHCVSS 6.0EG 8.22022-06-07
A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token validation of the session identifier, allows an unauthorized modified message to be executed in…
- CVE-2021-35941HIGHCVSS 7.5EG 7.52021-06-29
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerabi…
- CVE-2021-35943CRITICALCVSS 9.8EG 9.82021-09-29
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
- CVE-2021-35964CRITICALCVSS 7.3EG 9.82021-07-19
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the…
- CVE-2021-35973CRITICALCVSS 9.8EG 9.82021-06-30
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the ¤tsetting.htm substring to the HTTP query,…
- CVE-2021-35979HIGHCVSS 8.1EG 8.12021-10-08
An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication.
- CVE-2021-36124CRITICALCVSS 9.8EG 9.82021-07-13
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerab…
- CVE-2021-36128CRITICALCVSS 9.8EG 9.82021-07-02
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.
- CVE-2021-36166CRITICALCVSS 9.8EG 9.82022-03-01
An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
- CVE-2021-36306HIGHCVSS 8.1EG 8.12021-11-20
Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to gain access and perform actions on the affect…
- CVE-2021-36308CRITICALCVSS 5.9EG 9.82021-11-20
Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to gain access and perform actions on t…
- CVE-2021-3632HIGHCVSS 7.5EG 7.52022-08-26
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
- CVE-2021-36346MEDIUMCVSS 5.3EG 5.32022-01-25
Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver.
- CVE-2021-36350MEDIUMCVSS 5.9EG 5.92021-12-21
Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote unauthenticated attacker may potentially exploit this vulnerability and bypass one of the fa…
- CVE-2021-3636MEDIUMCVSS 4.6EG 4.62021-07-30
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely conne…
- CVE-2021-36368LOWCVSS 3.7EG 3.72022-03-13
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option,…
- CVE-2021-36369HIGHCVSS 7.5EG 7.52022-10-12
An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This atta…
- CVE-2021-36370HIGHCVSS 7.5EG 7.52021-08-30
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify it…
- CVE-2021-36460HIGHCVSS 7.8EG 7.82022-04-25
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows …
- CVE-2021-3652CRITICALCVSS 6.5EG 9.82022-04-18
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to…
- CVE-2021-36560CRITICALCVSS 9.8EG 9.82021-11-02
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.
- CVE-2021-36718MEDIUMCVSS 6.1EG 6.52021-12-08
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has b…
- CVE-2021-36721MEDIUMCVSS 4.4EG 5.32021-12-14
Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server.
- CVE-2021-36745CRITICALCVSS 9.8EG 9.82021-09-29
A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to …
- CVE-2021-36921HIGHCVSS 8.8EG 8.82021-08-12
AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an authentication chec…
- CVE-2021-36949HIGHCVSS 7.1EG 7.12021-08-12
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
- CVE-2021-37043HIGHCVSS 7.5EG 7.52021-12-07
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious application processes occupy system resources.
- CVE-2021-37054HIGHCVSS 7.5EG 7.52021-12-08
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-37100HIGHCVSS 7.5EG 7.52021-12-07
There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.
- CVE-2021-37123CRITICALCVSS 9.8EG 9.82021-10-11
There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain operation, the software does not insufficiently validate the user's identity. Successful ex…
- CVE-2021-37151MEDIUMCVSS 5.3EG 5.32021-09-01
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate be…
- CVE-2021-37153CRITICALCVSS 9.8EG 9.82021-08-25
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
- CVE-2021-37172HIGHCVSS 7.5EG 7.52021-08-10
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker usin…
- CVE-2021-37254HIGHCVSS 7.5EG 7.52021-10-28
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
- CVE-2021-37331MEDIUMCVSS 5.3EG 5.32021-10-04
Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by c…
- CVE-2021-37414HIGHCVSS 7.5EG 7.52021-09-10
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
- CVE-2021-37415CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-01
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
- CVE-2021-37417CRITICALCVSS 9.8EG 9.82021-08-30
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
- CVE-2021-37420MEDIUMCVSS 6.5EG 6.52021-09-21
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →