CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,933 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 61 of 99
- CVE-2022-26865MEDIUMCVSS 6.8EG 6.82022-05-26
Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in …
- CVE-2022-26870CRITICALCVSS 7.0EG 9.82022-10-21
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon s…
- CVE-2022-26971MEDIUMCVSS 5.3EG 5.32022-06-02
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.
- CVE-2022-26975HIGHCVSS 7.5EG 7.52022-06-02
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
- CVE-2022-27484MEDIUMCVSS 5.4EG 5.42022-08-03
A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.
- CVE-2022-27510CRITICALCVSS 9.8EG 9.82022-11-08
Unauthorized access to Gateway user capabilities
- CVE-2022-2752HIGHCVSS 5.5EG 7.82022-12-09
A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.
- CVE-2022-2757CRITICALCVSS 9.8EG 9.82022-12-13
Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing and modifying the application settings without authenticating by accessing a specific uniform resource…
- CVE-2022-2765CRITICALCVSS 6.3EG 9.82022-08-11
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to improper authentic…
- CVE-2022-27839MEDIUMCVSS 3.3EG 4.02022-04-11
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.
- CVE-2022-27874HIGHCVSS 6.8EG 7.22022-11-11
Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access.
- CVE-2022-27967MEDIUMCVSS 5.3EG 5.32022-09-08
Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a crafted GET request sent to /WebApp/SettingsExclusion/GetExclusionsProfiles.
- CVE-2022-27968MEDIUMCVSS 5.3EG 5.32022-09-08
Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of monitored files and profiles via a crafted GET request sent to /WebApp/SettingsFileMonitor/GetFileMonitorProfiles.
- CVE-2022-27969MEDIUMCVSS 5.3EG 5.32022-09-08
Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of decoy users via a crafted GET request sent to /WebApp/DeceptionUser/GetAllDeceptionUsers.
- CVE-2022-28106CRITICALCVSS 9.8EG 9.82022-05-20
Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POST request.
- CVE-2022-28321CRITICALCVSS 9.8EG 9.82022-09-19
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via …
- CVE-2022-28376HIGHCVSS 8.1EG 8.12022-04-03
Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, e.g., at the 10.0.0.1 IP address. The password (for the verizon username) is calculated by concaten…
- CVE-2022-28617CRITICALCVSS 9.8EG 9.82022-05-17
A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- CVE-2022-28620CRITICALCVSS 9.8EG 9.82022-06-24
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled bla…
- CVE-2022-28666MEDIUMCVSS 5.3EG 5.32022-07-21
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
- CVE-2022-28713MEDIUMCVSS 5.3EG 5.32022-07-04
Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Information without logging in to the product.
- CVE-2022-28771HIGHCVSS 7.5EG 7.52022-07-12
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole appli…
- CVE-2022-28790MEDIUMCVSS 4.0EG 4.02022-05-03
Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.
- CVE-2022-28860MEDIUMCVSS 5.9EG 5.92022-07-21
An authentication downgrade in the server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to achieve HTTP access to the camera.
- CVE-2022-28955HIGHCVSS 7.5EG 7.72022-05-18
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.
- CVE-2022-28993CRITICALCVSS 9.8EG 9.82022-05-20
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
- CVE-2022-29083MEDIUMCVSS 6.8EG 6.82022-08-09
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain …
- CVE-2022-29165CRITICALCVSS 10.0EG 10.02022-05-20
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions 2.1.15, 2.2.9, and 2.3.4 which would allow unauthenticated …
- CVE-2022-29237MEDIUMCVSS 5.4EG 5.42022-05-24
Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.14 and 11.7, users could pass along URLs for files belonging to organizations other than the user's own, which Opencast…
- CVE-2022-29334CRITICALCVSS 9.8EG 9.82022-05-24
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
- CVE-2022-29500HIGHCVSS 8.8EG 8.82022-05-05
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
- CVE-2022-29518HIGHCVSS 7.0EG 7.02022-05-18
Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, G…
- CVE-2022-29534HIGHCVSS 7.5EG 7.52022-04-20
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
- CVE-2022-29578MEDIUMCVSS 5.3EG 5.32022-06-24
Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information such as name, address, and daily energy usage.
- CVE-2022-29775CRITICALCVSS 9.8EG 9.82022-06-21
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
- CVE-2022-29838MEDIUMCVSS 4.3EG 4.62022-12-09
Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Di…
- CVE-2022-29858MEDIUMCVSS 4.3EG 4.32022-06-28
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
- CVE-2022-29865HIGHCVSS 7.5EG 7.52022-06-16
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.
- CVE-2022-29883MEDIUMCVSS 5.3EG 5.32022-05-20
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the web interface. This could allow an attacker to delete log files without authentication.
- CVE-2022-29893HIGHCVSS 8.1EG 8.82022-11-11
Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an authenticated user to potentially enable escalation of privilege via network access.
- CVE-2022-29934HIGHCVSS 7.8EG 7.82022-04-29
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.
- CVE-2022-30034HIGHCVSS 8.6EG 8.62022-06-02
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny ser…
- CVE-2022-30124MEDIUMCVSS 6.8EG 6.82022-09-23
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).
- CVE-2022-30150HIGHCVSS 7.5EG 7.52022-06-15
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
- CVE-2022-30229HIGHCVSS 7.2EG 7.22022-06-14
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data o…
- CVE-2022-30238HIGHCVSS 8.3EG 8.82022-06-02
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a session. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
- CVE-2022-30270CRITICALCVSS 9.8EG 9.82022-07-26
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software func…
- CVE-2022-30319HIGHCVSS 8.1EG 8.12022-07-28
Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a Saia Burgess Controls (SBC) PCD S-Bus authentication bypass issue. The affected components are characterized as: S-Bus…
- CVE-2022-30421HIGHCVSS 7.8EG 7.82023-01-31
Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(local) password authentication module.
- CVE-2022-30550HIGHCVSS 8.8EG 8.82022-07-17
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to pass…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →