CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,933 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 57 of 99
- CVE-2021-45495CRITICALCVSS 6.5EG 9.82021-12-26
NETGEAR D7000 devices before 1.0.1.68 are affected by authentication bypass.
- CVE-2021-45496CRITICALCVSS 9.1EG 9.82021-12-26
NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.
- CVE-2021-45497CRITICALCVSS 9.4EG 9.82021-12-26
NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.
- CVE-2021-45498CRITICALCVSS 6.5EG 9.82021-12-26
NETGEAR R6700v2 devices before 1.2.0.88 are affected by authentication bypass.
- CVE-2021-45499HIGHCVSS 8.2EG 8.82021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects R6900P before 1.3.3.140, R7000P before 1.3.3.140, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, RAX75 before 1.0.3.106, and RAX80 before …
- CVE-2021-45500CRITICALCVSS 9.6EG 9.62021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects R7000P before 1.3.3.140 and R8000 before 1.0.4.68.
- CVE-2021-45501CRITICALCVSS 9.4EG 9.82021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects AC2400 before 1.1.0.84, AC2600 before 1.1.0.84, D7000 before 1.0.1.82, R6020 before 1.0.0.52, R6080 before 1.0.0.52, R6120 before 1.0.0.80, R6220 before 1.1.0.110,…
- CVE-2021-45502CRITICALCVSS 9.6EG 9.62021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3…
- CVE-2021-45503CRITICALCVSS 9.6EG 9.62021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 befo…
- CVE-2021-45504CRITICALCVSS 9.6EG 9.82021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBR852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
- CVE-2021-45505CRITICALCVSS 9.6EG 9.62021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 befo…
- CVE-2021-45506CRITICALCVSS 9.6EG 9.62021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 befo…
- CVE-2021-45507CRITICALCVSS 9.6EG 9.82021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBW30 before 2.6.2.2, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17…
- CVE-2021-45508CRITICALCVSS 9.6EG 9.82021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, and RBR850 before…
- CVE-2021-45509CRITICALCVSS 9.6EG 9.82021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 befo…
- CVE-2021-45510HIGHCVSS 8.2EG 8.82021-12-26
NETGEAR XR1000 devices before 1.0.0.58 are affected by authentication bypass.
- CVE-2021-45511CRITICALCVSS 6.8EG 9.82021-12-26
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08-27, D7000 before 2021-08-27, R6220 before 2021-08-27, R6230 before 2021-08-27, R6260 befo…
- CVE-2021-45735HIGHCVSS 7.5EG 7.52022-02-04
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.
- CVE-2021-45786CRITICALCVSS 9.8EG 9.82022-03-16
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
- CVE-2021-45841HIGHCVSS 8.1EG 8.12022-04-25
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty has…
- CVE-2021-45890CRITICALCVSS 9.8EG 9.82021-12-27
basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.
- CVE-2021-45900MEDIUMCVSS 6.5EG 6.52022-03-30
Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be success…
- CVE-2021-45914CRITICALCVSS 9.8EG 9.82022-05-24
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
- CVE-2021-45915CRITICALCVSS 9.8EG 9.82022-05-24
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
- CVE-2021-45917HIGHCVSS 8.0EG 8.02022-01-03
The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer within the local area network can use the local registry information to launch server-sid…
- CVE-2021-46249MEDIUMCVSS 6.5EG 6.52022-02-15
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their ow…
- CVE-2021-46304HIGHCVSS 7.5EG 7.52022-08-10
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions), CP-8021 MASTER MODULE (All versions), CP-8022 MASTER MODULE WITH GPRS (All versions)…
- CVE-2021-46390MEDIUMCVSS 6.8EG 6.82022-03-21
An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and cause a Denial of Service (DoS). An attacker without access to securely protected data on a secure USB flash drive can …
- CVE-2021-46740HIGHCVSS 7.5EG 7.52022-04-11
The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-46742CRITICALCVSS 9.1EG 9.12022-04-11
The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.
- CVE-2021-46825CRITICALCVSS 9.1EG 9.12022-07-07
Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send …
- CVE-2022-0342CRITICALCVSS 9.8EG 9.82022-03-28
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmw…
- CVE-2022-0366HIGHCVSS 8.8EG 8.82022-02-02
An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.
- CVE-2022-0492CRITICALCVSS 7.8EG 9.0⚠ KEV2022-03-03
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges a…
- CVE-2022-0540CRITICALCVSS 9.8EG 9.82022-04-20
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and …
- CVE-2022-0547CRITICALCVSS 9.8EG 9.82022-03-18
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only…
- CVE-2022-0715CRITICALCVSS 9.1EG 9.12022-03-09
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Seri…
- CVE-2022-0730CRITICALCVSS 9.8EG 9.82022-03-03
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
- CVE-2022-0755MEDIUMCVSS 4.3EG 4.32022-03-07
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- CVE-2022-0862MEDIUMCVSS 3.1EG 5.32022-03-23
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the ex…
- CVE-2022-0910MEDIUMCVSS 6.5EG 6.52022-05-24
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmwa…
- CVE-2022-0916HIGHCVSS 8.4EG 8.82022-05-03
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
- CVE-2022-0985MEDIUMCVSS 4.3EG 4.32022-04-29
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.
- CVE-2022-0996HIGHCVSS 6.5EG 7.52022-03-23
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
- CVE-2022-1040CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-25
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
- CVE-2022-1049HIGHCVSS 8.8EG 8.82022-03-25
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been d…
- CVE-2022-1065HIGHCVSS 8.1EG 8.82022-04-19
A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions prior to R4 of 202…
- CVE-2022-1067MEDIUMCVSS 6.5EG 6.52022-04-11
Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting.
- CVE-2022-1084CRITICALCVSS 7.3EG 9.82022-03-29
A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authenticat…
- CVE-2022-1101CRITICALCVSS 7.3EG 9.82023-01-07
A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /royal_event/userregister.php. The manipulation leads to improper authent…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →