CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,933 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 59 of 99
- CVE-2022-22955CRITICALCVSS 9.8EG 9.82022-04-13
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed end…
- CVE-2022-22956CRITICALCVSS 9.8EG 9.82022-04-13
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed end…
- CVE-2022-22972CRITICALCVSS 9.8EG 9.82022-05-20
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access …
- CVE-2022-22990HIGHCVSS 7.8EG 8.82022-01-13
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation lo…
- CVE-2022-2302CRITICALCVSS 9.8EG 9.82022-07-11
Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password.
- CVE-2022-2303MEDIUMCVSS 4.3EG 4.32022-08-05
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement…
- CVE-2022-23126CRITICALCVSS 9.8EG 9.82022-01-24
TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Graf…
- CVE-2022-23134CRITICALCVSS 3.7EG 9.0⚠ KEV2022-01-13
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Fro…
- CVE-2022-23156MEDIUMCVSS 6.0EG 6.72022-04-01
Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could potentially exploit this vulnerability by providing invalid input in order to obtain a connection to WMS server.
- CVE-2022-23178CRITICALCVSS 9.8EG 9.82022-01-15
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interfac…
- CVE-2022-23220HIGHCVSS 7.8EG 7.82022-01-21
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, fo…
- CVE-2022-23232MEDIUMCVSS 4.9EG 4.92022-03-04
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled, expired, or locked external user accounts to access S3 data to which they previ…
- CVE-2022-23317HIGHCVSS 7.5EG 7.52022-02-15
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
- CVE-2022-23320HIGHCVSS 7.5EG 7.52022-02-07
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitiv…
- CVE-2022-2336CRITICALCVSS 9.8EG 9.82022-08-17
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrati…
- CVE-2022-23383CRITICALCVSS 9.1EG 9.12022-03-10
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulner…
- CVE-2022-23501MEDIUMCVSS 5.9EG 5.92022-12-14
TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in d…
- CVE-2022-23505MEDIUMCVSS 5.3EG 5.32022-12-13
Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A suc…
- CVE-2022-23540MEDIUMCVSS 6.4EG 6.42022-12-22
In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected i…
- CVE-2022-23541MEDIUMCVSS 5.0EG 5.02022-12-22
jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval function referring to the `secretOrPublicKey` argument from the rea…
- CVE-2022-23554MEDIUMCVSS 6.5EG 6.52022-12-28
Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL w…
- CVE-2022-23555CRITICALCVSS 9.4EG 9.42022-12-28
authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via th…
- CVE-2022-23600MEDIUMCVSS 5.3EG 5.32022-02-04
fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missing audience verification. This impacts deployments using SAML SSO in two specific cases: 1…
- CVE-2022-23635HIGHCVSS 7.5EG 7.52022-02-22
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted messa…
- CVE-2022-23652HIGHCVSS 8.8EG 8.82022-02-22
capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a proper authentication mechanism may use a malicious `Connection` header to start a privilege es…
- CVE-2022-23654HIGHCVSS 8.1EG 8.12022-02-22
Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page outside the allowed paths by specifying a different target page ID while keeping the path i…
- CVE-2022-23657CRITICALCVSS 10.0EG 10.02022-05-16
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that …
- CVE-2022-23658CRITICALCVSS 10.0EG 10.02022-05-16
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that …
- CVE-2022-23660CRITICALCVSS 10.0EG 10.02022-05-16
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that …
- CVE-2022-23691MEDIUMCVSS 6.8EG 6.82022-09-06
A vulnerability exists in certain AOS-CX switch models which could allow an attacker with access to the recovery console to bypass normal authentication. A successful exploit allows an attacker to bypass system authentication and achieve t…
- CVE-2022-23699HIGHCVSS 7.8EG 7.82022-04-04
A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- CVE-2022-23719HIGHCVSS 7.2EG 7.22022-06-30
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the l…
- CVE-2022-23722MEDIUMCVSS 6.5EG 6.52022-05-02
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
- CVE-2022-23723CRITICALCVSS 7.7EG 9.82022-05-02
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.
- CVE-2022-23724HIGHCVSS 6.4EG 8.12022-05-04
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have c…
- CVE-2022-23725HIGHCVSS 7.7EG 7.72022-06-30
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
- CVE-2022-23729HIGHCVSS 7.8EG 7.82022-03-04
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
- CVE-2022-23769CRITICALCVSS 7.5EG 9.82022-10-17
Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution.
- CVE-2022-23795CRITICALCVSS 9.8EG 9.82022-03-30
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
- CVE-2022-23807MEDIUMCVSS 4.3EG 4.32022-01-22
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
- CVE-2022-23849MEDIUMCVSS 6.6EG 6.62022-03-03
The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts.
- CVE-2022-23855CRITICALCVSS 9.8EG 9.82022-01-24
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account.
- CVE-2022-2393MEDIUMCVSS 5.7EG 5.72022-07-14
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another…
- CVE-2022-24047CRITICALCVSS 9.8EG 9.82022-02-18
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of…
- CVE-2022-24259CRITICALCVSS 9.8EG 9.82022-02-04
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.
- CVE-2022-24285HIGHCVSS 7.8EG 7.82022-03-10
Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority called ACCsvc through a named pipe. In this case, the Named Pipe is also give…
- CVE-2022-24286HIGHCVSS 7.8EG 7.82022-03-10
Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In this case, the Named …
- CVE-2022-24331CRITICALCVSS 9.8EG 9.82022-02-25
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
- CVE-2022-24422CRITICALCVSS 9.6EG 9.82022-05-26
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.
- CVE-2022-24551HIGHCVSS 8.8EG 8.82022-02-06
A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (including system/administrator user) using any available us…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →