CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,933 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 60 of 99
- CVE-2022-24562CRITICALCVSS 9.8EG 9.82022-06-16
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data…
- CVE-2022-24738HIGHCVSS 8.1EG 8.12022-03-07
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed funds from user addresses. To do this an attacker must create a new chain which does not enfor…
- CVE-2022-24740MEDIUMCVSS 5.0EG 5.02022-03-14
Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have their authentication cookie replaced with an authentication cookie from another user, effectiv…
- CVE-2022-24748MEDIUMCVSS 6.8EG 6.82022-03-09
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result …
- CVE-2022-24813MEDIUMCVSS 5.3EG 5.32022-04-04
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this issue is available …
- CVE-2022-24857HIGHCVSS 7.3EG 7.32022-04-15
django-mfa3 is a library that implements multi factor authentication for the django web framework. It achieves this by modifying the regular login view. Django however has a second login view for its admin area. This second login view was …
- CVE-2022-24882CRITICALCVSS 9.1EG 9.12022-04-26
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP base…
- CVE-2022-24883HIGHCVSS 7.4EG 7.42022-04-26
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file p…
- CVE-2022-24885LOWCVSS 2.0EG 2.02022-04-27
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.1, users can bypass a lock on the Nextcloud app on an Android device by repeatedly reopening the app. Version 3.19.1 cont…
- CVE-2022-24901HIGHCVSS 7.5EG 7.52022-05-04
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL …
- CVE-2022-24976CRITICALCVSS 9.1EG 9.12022-02-14
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
- CVE-2022-24985HIGHCVSS 8.8EG 8.82022-02-16
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organizat…
- CVE-2022-25027HIGHCVSS 7.5EG 7.52023-01-12
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
- CVE-2022-2503MEDIUMCVSS 6.9EG 6.92022-08-12
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users with root privilege…
- CVE-2022-25155HIGHCVSS 8.1EG 8.12022-04-01
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R se…
- CVE-2022-25157CRITICALCVSS 9.1EG 9.12022-04-01
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R se…
- CVE-2022-25226CRITICALCVSS 10.0EG 10.02022-04-18
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on t…
- CVE-2022-25262CRITICALCVSS 9.8EG 9.82022-02-25
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
- CVE-2022-2533HIGHCVSS 6.5EG 7.42022-10-17
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication…
- CVE-2022-25359CRITICALCVSS 9.1EG 9.12022-02-26
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
- CVE-2022-25369CRITICALCVSS 9.8EG 9.82026-01-23
An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an a…
- CVE-2022-2552MEDIUMCVSS 5.3EG 5.32022-08-22
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
- CVE-2022-2553MEDIUMCVSS 6.5EG 6.52022-07-28
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with …
- CVE-2022-25626MEDIUMCVSS 5.3EG 5.32022-12-16
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
- CVE-2022-25640HIGHCVSS 7.5EG 7.52022-02-24
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
- CVE-2022-25652CRITICALCVSS 9.0EG 9.02022-09-16
Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking
- CVE-2022-25667HIGHCVSS 7.5EG 7.52022-11-15
Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking
- CVE-2022-25685HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVE-2022-2572CRITICALCVSS 9.8EG 9.82022-11-01
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.
- CVE-2022-25768HIGHCVSS 7.0EG 7.02024-09-18
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mauti…
- CVE-2022-25816MEDIUMCVSS 4.1EG 4.62022-03-10
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication
- CVE-2022-25817MEDIUMCVSS 4.0EG 4.02022-03-10
Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.
- CVE-2022-25825MEDIUMCVSS 6.2EG 6.22022-03-10
Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.
- CVE-2022-25831MEDIUMCVSS 2.0EG 4.62022-04-11
Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.
- CVE-2022-25832MEDIUMCVSS 4.0EG 6.82022-04-11
Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.
- CVE-2022-25833LOWCVSS 3.3EG 3.32022-04-11
Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.
- CVE-2022-25915HIGHCVSS 8.8EG 8.82022-03-31
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmw…
- CVE-2022-26034CRITICALCVSS 9.1EG 9.12022-04-15
Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00, and B/M9000 VP R8.…
- CVE-2022-26091MEDIUMCVSS 5.7EG 6.82022-04-11
Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.
- CVE-2022-26119HIGHCVSS 7.8EG 7.82022-11-02
A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.
- CVE-2022-26136CRITICALCVSS 9.8EG 9.82022-07-20
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. …
- CVE-2022-26504HIGHCVSS 8.8EG 8.82022-03-17
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe
- CVE-2022-26508HIGHCVSS 4.3EG 7.52022-11-11
Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access.
- CVE-2022-26562CRITICALCVSS 9.8EG 9.82022-04-01
An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Plat…
- CVE-2022-2662CRITICALCVSS 9.6EG 9.82022-08-16
Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access to the device.
- CVE-2022-2664CRITICALCVSS 7.3EG 9.82022-08-05
A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulat…
- CVE-2022-26724MEDIUMCVSS 5.5EG 5.52022-05-26
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication.
- CVE-2022-2675MEDIUMCVSS 6.5EG 6.52022-08-05
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be af…
- CVE-2022-26845CRITICALCVSS 8.7EG 9.82022-11-11
Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- CVE-2022-26858HIGHCVSS 6.1EG 7.82022-09-06
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →