CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,933 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 56 of 99
- CVE-2021-43116HIGHCVSS 8.8EG 8.82022-07-05
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
- CVE-2021-43136CRITICALCVSS 9.8EG 9.82021-11-10
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
- CVE-2021-4314MEDIUMCVSS 5.3EG 5.32023-01-18
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue…
- CVE-2021-43175HIGHCVSS 7.5EG 7.52021-12-07
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOaut…
- CVE-2021-43183CRITICALCVSS 9.8EG 9.82021-11-09
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
- CVE-2021-43203HIGHCVSS 7.5EG 7.52021-11-09
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
- CVE-2021-43355CRITICALCVSS 7.3EG 9.82022-01-21
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users…
- CVE-2021-43394CRITICALCVSS 9.8EG 9.82022-01-24
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.
- CVE-2021-43414HIGHCVSS 7.0EG 7.02021-11-07
An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middle attacks, which can be exploited for local privilege escalation to get full root access.
- CVE-2021-43444HIGHCVSS 7.5EG 7.52023-01-23
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.
- CVE-2021-43445CRITICALCVSS 9.8EG 9.82023-01-23
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.
- CVE-2021-43447HIGHCVSS 7.5EG 7.52023-01-23
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.
- CVE-2021-43483HIGHCVSS 8.0EG 8.02022-04-08
An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.
- CVE-2021-43563HIGHCVSS 8.8EG 8.82021-11-10
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io…
- CVE-2021-43786CRITICALCVSS 9.8EG 9.82021-11-29
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. User…
- CVE-2021-43833HIGHCVSS 8.1EG 8.12021-12-16
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address. Th…
- CVE-2021-43834CRITICALCVSS 9.1EG 9.12021-12-16
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authenticat…
- CVE-2021-43931CRITICALCVSS 9.8EG 9.82021-12-06
The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
- CVE-2021-43935CRITICALCVSS 8.1EG 9.82021-12-15
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the applicati…
- CVE-2021-43946MEDIUMCVSS 6.5EG 6.52022-01-05
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. Th…
- CVE-2021-43950MEDIUMCVSS 4.3EG 4.32022-02-15
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source featu…
- CVE-2021-43999HIGHCVSS 8.8EG 8.82022-01-11
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.
- CVE-2021-44032HIGHCVSS 7.5EG 7.52022-03-10
TP-Link Omada SDN Software Controller before 5.0.15 does not check if the authentication method specified in a connection request is allowed. An attacker can bypass the captive portal authentication process by using the downgraded "no auth…
- CVE-2021-44056CRITICALCVSS 7.1EG 9.82022-05-05
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in…
- CVE-2021-44057CRITICALCVSS 7.1EG 9.82022-05-05
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in…
- CVE-2021-44077CRITICALCVSS 9.8EG 9.8⚠ KEV2021-11-29
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechn…
- CVE-2021-44152CRITICALCVSS 9.8EG 9.82021-12-13
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change t…
- CVE-2021-44458HIGHCVSS 8.3EG 8.32022-01-10
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would…
- CVE-2021-44514CRITICALCVSS 9.8EG 9.82021-12-09
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
- CVE-2021-44515CRITICALCVSS 9.8EG 9.8⚠ KEV2021-12-12
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. F…
- CVE-2021-44524CRITICALCVSS 9.8EG 9.82021-12-14
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All version…
- CVE-2021-44525CRITICALCVSS 9.8EG 9.82021-12-20
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
- CVE-2021-44526CRITICALCVSS 9.8EG 9.82021-12-23
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
- CVE-2021-44675CRITICALCVSS 9.8EG 9.82021-12-20
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.
- CVE-2021-44676CRITICALCVSS 9.8EG 9.82021-12-20
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.
- CVE-2021-44736CRITICALCVSS 9.8EG 9.82022-01-20
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
- CVE-2021-44757CRITICALCVSS 9.1EG 9.12022-01-18
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
- CVE-2021-44759HIGHCVSS 8.1EG 8.12022-03-23
Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
- CVE-2021-44848MEDIUMCVSS 5.3EG 5.32021-12-13
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.
- CVE-2021-44937MEDIUMCVSS 5.3EG 5.32021-12-14
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailbox has been occupie…
- CVE-2021-44949CRITICALCVSS 9.8EG 9.82021-12-14
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
- CVE-2021-44971CRITICALCVSS 9.8EG 9.82022-01-28
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated …
- CVE-2021-45035MEDIUMCVSS 6.3EG 6.32022-09-23
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.
- CVE-2021-45036HIGHCVSS 8.7EG 8.72022-11-28
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.
- CVE-2021-45079CRITICALCVSS 9.1EG 9.12022-01-31
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even w…
- CVE-2021-45331CRITICALCVSS 9.8EG 9.82022-02-09
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.
- CVE-2021-45347HIGHCVSS 7.5EG 7.52022-02-14
An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.
- CVE-2021-45379HIGHCVSS 8.8EG 8.82021-12-30
Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.
- CVE-2021-45389CRITICALCVSS 9.8EG 9.82022-01-04
A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command…
- CVE-2021-45420CRITICALCVSS 9.8EG 9.82022-02-14
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system withou…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →