CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,933 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 62 of 99
- CVE-2022-30623CRITICALCVSS 5.9EG 9.82022-07-18
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.
- CVE-2022-30624HIGHCVSS 6.8EG 7.52022-07-18
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.
- CVE-2022-30749HIGHCVSS 3.3EG 7.82022-06-07
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.
- CVE-2022-30755HIGHCVSS 7.3EG 7.82022-07-12
Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.
- CVE-2022-30995CRITICALCVSS 7.5EG 9.32023-05-03
Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.
- CVE-2022-31011HIGHCVSS 7.8EG 7.82022-05-31
TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication proces…
- CVE-2022-31013CRITICALCVSS 9.1EG 9.12022-05-31
Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAcces…
- CVE-2022-31020HIGHCVSS 8.8EG 8.82022-09-06
Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` request handler in Indy-Node allows an improperly authenticated attacker to remotely execute…
- CVE-2022-31083HIGHCVSS 8.6EG 8.62022-06-17
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, aut…
- CVE-2022-31122CRITICALCVSS 9.8EG 9.82022-10-18
Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain details of SAML IdP metadata, and configures their own SAML on th…
- CVE-2022-31125CRITICALCVSS 10.0EG 10.02022-07-06
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a s…
- CVE-2022-31131MEDIUMCVSS 5.4EG 5.42022-07-06
Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have b…
- CVE-2022-31164HIGHCVSS 7.5EG 7.52022-07-22
Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been patched in version…
- CVE-2022-3119HIGHCVSS 7.5EG 7.52022-09-26
The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls,…
- CVE-2022-31461HIGHCVSS 7.4EG 7.42022-06-02
Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message.
- CVE-2022-31463HIGHCVSS 8.2EG 8.22022-06-02
Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used.
- CVE-2022-3152HIGHCVSS 8.8EG 8.82022-09-07
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
- CVE-2022-3156HIGHCVSS 7.8EG 7.82022-12-27
A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a …
- CVE-2022-31656CRITICALCVSS 9.8EG 9.82022-08-05
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access …
- CVE-2022-31685CRITICALCVSS 9.8EG 9.82022-11-09
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the a…
- CVE-2022-31686CRITICALCVSS 9.8EG 9.82022-11-09
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to…
- CVE-2022-31701MEDIUMCVSS 5.3EG 5.32022-12-14
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.
- CVE-2022-3173MEDIUMCVSS 4.3EG 4.32022-09-17
Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
- CVE-2022-3218CRITICALCVSS 9.8EG 9.82022-09-19
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.
- CVE-2022-32276HIGHCVSS 7.5EG 7.52022-06-17
Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability
- CVE-2022-32282HIGHCVSS 8.8EG 8.82022-08-22
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, leading to increased p…
- CVE-2022-32429CRITICALCVSS 9.8EG 9.82022-08-10
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, l…
- CVE-2022-32514CRITICALCVSS 9.8EG 9.82023-01-30
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0…
- CVE-2022-32560HIGHCVSS 7.5EG 7.52022-06-13
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
- CVE-2022-32570HIGHCVSS 6.7EG 7.82023-02-16
Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-32928MEDIUMCVSS 5.3EG 5.32022-11-01
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.
- CVE-2022-32935MEDIUMCVSS 4.6EG 4.62022-11-01
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.
- CVE-2022-32971HIGHCVSS 3.1EG 7.22023-02-16
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access.
- CVE-2022-33139CRITICALCVSS 9.8EG 9.82022-06-21
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-def…
- CVE-2022-33202HIGHCVSS 8.1EG 8.12022-06-27
Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information …
- CVE-2022-33242HIGHCVSS 7.8EG 7.82023-03-10
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
- CVE-2022-33689MEDIUMCVSS 6.2EG 6.22022-07-12
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.
- CVE-2022-33720LOWCVSS 2.4EG 2.42022-08-05
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.
- CVE-2022-33732HIGHCVSS 6.2EG 7.12022-08-05
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.
- CVE-2022-33736HIGHCVSS 7.5EG 7.52022-07-12
A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (All versions < V13.2.20220624). The affected applications do not properly validate login information during authenticati…
- CVE-2022-33750CRITICALCVSS 9.8EG 9.82022-06-16
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.
- CVE-2022-33862MEDIUMCVSS 6.7EG 6.72024-11-25
IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.
- CVE-2022-33946HIGHCVSS 5.6EG 7.82023-02-16
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-34149CRITICALCVSS 9.8EG 9.82022-08-22
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
- CVE-2022-34155HIGHCVSS 8.8EG 8.82023-07-18
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
- CVE-2022-34267CRITICALCVSS 9.8EG 9.82023-12-25
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customiz…
- CVE-2022-34331CRITICALCVSS 5.5EG 9.82022-11-11
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.
- CVE-2022-34372CRITICALCVSS 9.8EG 9.82022-09-01
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypa…
- CVE-2022-34379CRITICALCVSS 9.4EG 9.82022-09-01
Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized acce…
- CVE-2022-34380CRITICALCVSS 9.3EG 9.32022-09-01
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass a…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →