CWE-287— Improper Authentication
4,308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 60 of 87
- CVE-2022-41263MEDIUMCVSS 4.3EG 4.32022-12-12
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that…
- CVE-2022-41436CRITICALCVSS 9.1EG 9.12022-10-14
An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.html.
- CVE-2022-41545MEDIUMCVSS 6.4EG 9.82025-02-18
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and pas…
- CVE-2022-41579MEDIUMCVSS 6.5EG 6.52022-12-28
There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect to the band.
- CVE-2022-41590MEDIUMCVSS 5.5EG 5.52022-12-20
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.
- CVE-2022-41648CRITICALCVSS 9.8EG 9.82022-10-28
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may…
- CVE-2022-41678HIGHCVSS 8.8EG 9.02023-11-28
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpR…
- CVE-2022-41737HIGHCVSS 7.1EG 7.12024-02-17
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.
- CVE-2022-41738HIGHCVSS 7.5EG 7.52024-02-17
IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.
- CVE-2022-41912CRITICALCVSS 9.1EG 9.12022-11-28
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds ot…
- CVE-2022-41985HIGHCVSS 8.6EG 8.62023-05-10
An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can sen…
- CVE-2022-42233CRITICALCVSS 9.8EG 9.82022-10-20
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
- CVE-2022-42453MEDIUMCVSS 6.9EG 6.52022-12-19
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
- CVE-2022-42458CRITICALCVSS 9.8EG 9.82022-12-07
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a …
- CVE-2022-42463HIGHCVSS 8.3EG 8.82022-10-14
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm …
- CVE-2022-42488HIGHCVSS 8.4EG 7.82022-10-14
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable securit…
- CVE-2022-4287HIGHCVSS 8.8EG 8.82022-12-21
Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malicious user to access the application.
- CVE-2022-42951HIGHCVSS 8.1EG 8.12023-02-06
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authenticati…
- CVE-2022-43400CRITICALCVSS 9.8EG 9.82022-10-21
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of…
- CVE-2022-43451HIGHCVSS 8.4EG 6.52022-11-03
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it …
- CVE-2022-43504MEDIUMCVSS 5.3EG 5.32022-12-05
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also pro…
- CVE-2022-43528MEDIUMCVSS 4.8EG 6.52023-01-05
Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a username and password a…
- CVE-2022-43549CRITICALCVSS 9.8EG 9.82022-12-05
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
- CVE-2022-43557MEDIUMCVSS 5.3EG 5.32022-12-05
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump.…
- CVE-2022-43620HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hand…
- CVE-2022-43690MEDIUMCVSS 6.3EG 6.32022-11-14
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authentication bypass could occur if using this functionality. Remediate by updating to Concrete C…
- CVE-2022-43782CRITICALCVSS 9.8EG 9.82022-11-17
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. Thi…
- CVE-2022-43900MEDIUMCVSS 5.3EG 6.52022-12-01
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827.
- CVE-2022-43978MEDIUMCVSS 5.6EG 3.72023-01-27
There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker w…
- CVE-2022-44013CRITICALCVSS 9.1EG 9.12022-12-25
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authentication because the password in a Credential Object is not checked.
- CVE-2022-44022MEDIUMCVSS 5.3EG 5.32022-10-30
PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts.
- CVE-2022-44037HIGHCVSS 8.8EG 8.82022-11-29
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attackers to access sensitive data and execute specific commands and functions with full admin ri…
- CVE-2022-44244MEDIUMCVSS 6.6EG 6.62022-11-09
An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.
- CVE-2022-4441HIGHCVSS 7.6EG 8.82023-01-31
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 0…
- CVE-2022-44569HIGHCVSS 7.8EG 8.82023-11-03
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
- CVE-2022-44574HIGHCVSS 7.5EG 7.52023-03-10
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.
- CVE-2022-44595MEDIUMCVSS 5.3EG 5.32024-03-21
Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.
- CVE-2022-44610MEDIUMCVSS 5.4EG 5.42023-05-10
Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.
- CVE-2022-44620HIGHCVSS 8.8EG 8.82022-12-07
Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- CVE-2022-44801CRITICALCVSS 9.8EG 9.82022-11-22
D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
- CVE-2022-45118MEDIUMCVSS 6.2EG 5.52022-12-08
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information …
- CVE-2022-45124HIGHCVSS 7.5EG 7.52023-03-20
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can sniff ne…
- CVE-2022-45168MEDIUMCVSS 6.5EG 6.52024-06-10
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application…
- CVE-2022-45173CRITICALCVSS 9.8EG 9.82023-04-14
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successfu…
- CVE-2022-45174CRITICALCVSS 9.8EG 9.82023-04-14
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness …
- CVE-2022-45378CRITICALCVSS 9.8EG 9.82022-11-14
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are avail…
- CVE-2022-45430LOWCVSS 3.7EG 3.72022-12-27
Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could en…
- CVE-2022-45431HIGHCVSS 7.5EG 7.52022-12-27
Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unau…
- CVE-2022-45432MEDIUMCVSS 5.3EG 5.32022-12-27
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticate…
- CVE-2022-45433LOWCVSS 3.7EG 3.72022-12-27
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker …
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →