CWE-287— Improper Authentication
4,308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 61 of 87
- CVE-2022-45434MEDIUMCVSS 5.9EG 5.92022-12-27
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an …
- CVE-2022-45456HIGHCVSS 7.5EG 3.32023-04-26
Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161.
- CVE-2022-45724MEDIUMCVSS 5.4EG 5.42023-02-13
Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an att…
- CVE-2022-45860MEDIUMCVSS 5.3EG 5.32023-05-03
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated a…
- CVE-2022-45877HIGHCVSS 8.3EG 5.32022-12-08
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
- CVE-2022-45922HIGHCVSS 8.8EG 8.82023-01-18
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, whi…
- CVE-2022-45933CRITICALCVSS 9.8EG 9.82022-11-27
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the…
- CVE-2022-46145HIGHCVSS 8.1EG 8.12022-12-02
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in …
- CVE-2022-46146MEDIUMCVSS 6.2EG 6.22022-11-29
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in au…
- CVE-2022-46170HIGHCVSS 8.6EG 8.62022-12-22
CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHa…
- CVE-2022-46172MEDIUMCVSS 6.4EG 6.42022-12-28
authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would ci…
- CVE-2022-46313MEDIUMCVSS 5.3EG 5.32022-12-20
The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.
- CVE-2022-46316CRITICALCVSS 9.8EG 9.82022-12-20
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
- CVE-2022-46400MEDIUMCVSS 5.4EG 5.42022-12-19
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
- CVE-2022-46411HIGHCVSS 8.8EG 8.82022-12-04
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
- CVE-2022-46773MEDIUMCVSS 4.3EG 6.52023-03-15
IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.
- CVE-2022-46774MEDIUMCVSS 5.4EG 6.52023-03-15
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.
- CVE-2022-46829HIGHCVSS 7.1EG 8.82022-12-08
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
- CVE-2022-46875MEDIUMCVSS 6.5EG 6.52022-12-22
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. T…
- CVE-2022-4693CRITICALCVSS 9.8EG 9.82023-01-23
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily quer…
- CVE-2022-47003CRITICALCVSS 9.8EG 9.82023-02-01
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
- CVE-2022-47209HIGHCVSS 8.8EG 8.82022-12-16
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.
- CVE-2022-4722HIGHCVSS 7.2EG 7.22022-12-27
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- CVE-2022-47408CRITICALCVSS 9.1EG 9.12022-12-14
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribin…
- CVE-2022-47508HIGHCVSS 7.5EG 7.52023-02-15
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.
- CVE-2022-47633HIGHCVSS 8.1EG 8.12022-12-23
An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fi…
- CVE-2022-47700HIGHCVSS 7.5EG 7.52023-01-31
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect Access Control. Improper authentication allows requests to be made to back-end scripts without a valid …
- CVE-2022-4779HIGHCVSS 7.5EG 9.82022-12-29
StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web server feature activate…
- CVE-2022-47848HIGHCVSS 7.5EG 7.52023-09-15
An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml …
- CVE-2022-47974MEDIUMCVSS 6.5EG 6.52023-01-06
The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth process to restart.
- CVE-2022-47976HIGHCVSS 7.5EG 7.52023-01-06
The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.
- CVE-2022-48066CRITICALCVSS 9.8EG 9.82023-01-27
An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.
- CVE-2022-48195CRITICALCVSS 9.8EG 9.82022-12-31
An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty). This ca…
- CVE-2022-48254MEDIUMCVSS 4.6EG 4.62023-02-27
There is a data processing error vulnerability in Leia-B29 2.0.0.49(M03). Successful exploitation could bypass lock screen authentication.
- CVE-2022-48294HIGHCVSS 7.5EG 7.52023-02-09
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-48305MEDIUMCVSS 5.5EG 5.52023-02-27
There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail.
- CVE-2022-48314MEDIUMCVSS 6.5EG 6.52023-04-16
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2022-48364MEDIUMCVSS 4.3EG 4.32023-03-06
The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server's representative account, resulting in moderator identity disclosure when a moderator approves the …
- CVE-2022-48494HIGHCVSS 7.5EG 7.52023-06-19
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
- CVE-2022-48496HIGHCVSS 7.5EG 7.52023-06-19
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
- CVE-2022-4861MEDIUMCVSS 4.8EG 4.92022-12-30
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
- CVE-2022-48618HIGHCVSS 7.0EG 9.0⚠ KEV2024-01-09
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. A…
- CVE-2022-4874HIGHCVSS 7.5EG 7.52023-01-11
Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the …
- CVE-2023-0035MEDIUMCVSS 6.5EG 7.82023-01-09
softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with hi…
- CVE-2023-0036MEDIUMCVSS 6.5EG 7.82023-01-09
platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high pri…
- CVE-2023-0105MEDIUMCVSS 6.5EG 6.52023-01-13
A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.
- CVE-2023-0117MEDIUMCVSS 5.3EG 5.32023-05-26
The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime.
- CVE-2023-0209HIGHCVSS 8.2EG 8.22023-04-22
NVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA is missing, which may lead to arbitrary code execution, denial of service, escalation of privileges assisted by a firmwa…
- CVE-2023-0228HIGHCVSS 8.8EG 8.82023-03-02
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
- CVE-2023-0264MEDIUMCVSS 5.0EG 5.02023-08-04
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to imperson…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →