CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,931 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 54 of 99
- CVE-2021-37545HIGHCVSS 7.5EG 7.52021-08-06
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
- CVE-2021-37580CRITICALCVSS 9.8EG 9.82021-11-16
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0
- CVE-2021-37597CRITICALCVSS 9.8EG 9.82021-08-19
WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
- CVE-2021-37624HIGHCVSS 7.5EG 7.52021-10-25
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticat…
- CVE-2021-37736CRITICALCVSS 9.8EG 9.82021-10-15
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.…
- CVE-2021-37741HIGHCVSS 8.8EG 8.82021-09-21
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.
- CVE-2021-3784MEDIUMCVSS 5.3EG 5.32023-10-04
Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from the 'Garuda settings manager', an insecure procedure is performed that keeps the created use…
- CVE-2021-3788MEDIUMCVSS 6.8EG 6.82021-11-12
An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.
- CVE-2021-37927CRITICALCVSS 9.8EG 9.82021-09-22
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
- CVE-2021-38137HIGHCVSS 8.1EG 8.12021-08-06
Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.
- CVE-2021-38161HIGHCVSS 8.1EG 8.12021-11-03
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.
- CVE-2021-3827MEDIUMCVSS 6.8EG 6.82022-08-23
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest an…
- CVE-2021-38299CRITICALCVSS 9.8EG 9.82021-09-27
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.
- CVE-2021-38376MEDIUMCVSS 5.3EG 5.32021-11-22
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
- CVE-2021-38412CRITICALCVSS 9.6EG 9.82021-09-17
Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an attacker to enable …
- CVE-2021-3849CRITICALCVSS 9.8EG 9.82022-04-22
An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on th…
- CVE-2021-3850CRITICALCVSS 9.1EG 9.12022-01-25
Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
- CVE-2021-38513CRITICALCVSS 9.6EG 9.82021-08-11
Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, MK62 before 1.0.6.110, MR60 before 1.0.6.1…
- CVE-2021-38514LOWCVSS 2.4EG 2.72021-08-11
Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1.1.00.34, D6220 before 1.0.0.48, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D…
- CVE-2021-38618HIGHCVSS 7.4EG 8.12021-10-04
In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an account. This occurs because of JSESSIONID mi…
- CVE-2021-38647CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-15
Open Management Infrastructure Remote Code Execution Vulnerability
- CVE-2021-38648CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-15
Open Management Infrastructure Elevation of Privilege Vulnerability
- CVE-2021-38679MEDIUMCVSS 6.5EG 6.52022-02-11
An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the…
- CVE-2021-38686HIGHCVSS 8.8EG 8.82021-11-26
An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the followin…
- CVE-2021-38688HIGHCVSS 7.1EG 7.12021-12-29
An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following ve…
- CVE-2021-38696HIGHCVSS 7.5EG 7.52022-01-18
SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.
- CVE-2021-38878HIGHCVSS 7.5EG 7.52022-04-27
IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.
- CVE-2021-3897CRITICALCVSS 9.8EG 9.82022-04-22
An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute co…
- CVE-2021-39064HIGHCVSS 7.5EG 7.52021-12-13
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.
- CVE-2021-39119MEDIUMCVSS 5.3EG 5.32021-09-01
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue no…
- CVE-2021-39138MEDIUMCVSS 4.8EG 4.82021-08-19
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup users and also allow users to login anonymously. Prior to version 4.5.1, when an anonymous us…
- CVE-2021-39165HIGHCVSS 8.1EG 8.12021-08-26
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensit…
- CVE-2021-39177HIGHCVSS 7.4EG 7.42021-08-30
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can connect to the server to forge a LoginPacket with manipulated JWT token allowing impersonat…
- CVE-2021-39196HIGHCVSS 7.7EG 7.72021-09-07
pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter and without adequat…
- CVE-2021-39215HIGHCVSS 7.5EG 7.52021-09-15
Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be…
- CVE-2021-39226CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-05
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /ap…
- CVE-2021-39296CRITICALCVSS 10.0EG 10.02021-09-09
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
- CVE-2021-3967HIGHCVSS 8.8EG 8.82022-02-26
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
- CVE-2021-3979MEDIUMCVSS 6.5EG 6.52022-08-25
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confide…
- CVE-2021-39872MEDIUMCVSS 6.5EG 6.52021-10-05
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
- CVE-2021-39890LOWCVSS 3.1EG 3.12021-12-06
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
- CVE-2021-39916MEDIUMCVSS 4.3EG 4.32021-12-13
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 b…
- CVE-2021-40013MEDIUMCVSS 6.5EG 6.52022-07-12
Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect integrity.
- CVE-2021-40130MEDIUMCVSS 4.9EG 4.92021-11-19
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restric…
- CVE-2021-40338MEDIUMCVSS 3.7EG 5.32022-01-28
Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue …
- CVE-2021-40342CRITICALCVSS 7.1EG 9.82023-01-05
In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected…
- CVE-2021-40350CRITICALCVSS 9.8EG 9.82021-09-01
webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspecified Cookie header. Authentication bypass can be achieved by including an administrative c…
- CVE-2021-40376HIGHCVSS 7.8EG 7.82022-03-10
otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP p…
- CVE-2021-40380HIGHCVSS 7.5EG 7.52021-09-01
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials.
- CVE-2021-40404CRITICALCVSS 6.5EG 9.82022-01-28
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to tri…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →