CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,935 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 65 of 99
- CVE-2022-39366CRITICALCVSS 9.9EG 9.92022-10-28
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as…
- CVE-2022-39387CRITICALCVSS 9.1EG 9.12022-11-04
XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has an OpenID provider configured through its xwiki.properties, it is possible to provide a third party provider its detai…
- CVE-2022-39801HIGHCVSS 7.5EG 7.52022-09-13
SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful explo…
- CVE-2022-39892CRITICALCVSS 3.6EG 9.82022-11-09
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.
- CVE-2022-39899MEDIUMCVSS 5.7EG 5.72022-12-08
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.
- CVE-2022-39901MEDIUMCVSS 6.5EG 6.52022-12-08
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.
- CVE-2022-3993CRITICALCVSS 9.4EG 9.82022-11-14
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
- CVE-2022-4001HIGHCVSS 7.3EG 7.32024-07-31
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.
- CVE-2022-4002HIGHCVSS 7.2EG 7.22024-07-31
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
- CVE-2022-40144CRITICALCVSS 9.8EG 9.82022-09-19
A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.
- CVE-2022-40242CRITICALCVSS 7.5EG 9.82022-12-05
MegaRAC Default Credentials Vulnerability
- CVE-2022-40259CRITICALCVSS 8.3EG 9.82022-12-05
MegaRAC Default Credentials Vulnerability
- CVE-2022-4041HIGHCVSS 5.9EG 8.82023-01-31
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 0…
- CVE-2022-40494CRITICALCVSS 9.8EG 9.82022-10-06
NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.
- CVE-2022-40521HIGHCVSS 7.5EG 7.52023-06-06
Transient DOS due to improper authorization in Modem
- CVE-2022-40536HIGHCVSS 7.5EG 7.52023-06-06
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
- CVE-2022-40602CRITICALCVSS 9.8EG 9.82022-11-22
A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authentica…
- CVE-2022-40616HIGHCVSS 8.1EG 8.12022-09-21
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tasks they should not have access to. IBM X-Force ID: 236311.
- CVE-2022-40622HIGHCVSS 8.8EG 8.82022-09-13
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's…
- CVE-2022-40664CRITICALCVSS 9.8EG 9.82022-10-12
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
- CVE-2022-40684CRITICALCVSS 9.8EG 9.8⚠ KEV2022-10-18
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 an…
- CVE-2022-40703MEDIUMCVSS 5.2EG 6.12022-10-26
CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass appl…
- CVE-2022-40723MEDIUMCVSS 6.5EG 6.52023-04-25
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
- CVE-2022-40966HIGHCVSS 8.8EG 8.82022-12-07
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlie…
- CVE-2022-4126CRITICALCVSS 9.6EG 9.82023-03-27
Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects RCCMD: before 4.40 230207.
- CVE-2022-41263MEDIUMCVSS 4.3EG 4.32022-12-12
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that…
- CVE-2022-41436CRITICALCVSS 9.1EG 9.12022-10-14
An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.html.
- CVE-2022-41545CRITICALCVSS 6.4EG 9.82025-02-18
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and pas…
- CVE-2022-41579MEDIUMCVSS 6.5EG 6.52022-12-28
There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect to the band.
- CVE-2022-41590MEDIUMCVSS 5.5EG 5.52022-12-20
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.
- CVE-2022-41648CRITICALCVSS 9.8EG 9.82022-10-28
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may…
- CVE-2022-41678CRITICALCVSS 8.8EG 9.02023-11-28
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpR…
- CVE-2022-41737HIGHCVSS 7.1EG 7.12024-02-17
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.
- CVE-2022-41738HIGHCVSS 7.5EG 7.52024-02-17
IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.
- CVE-2022-41912CRITICALCVSS 9.1EG 9.12022-11-28
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds ot…
- CVE-2022-41985HIGHCVSS 8.6EG 8.62023-05-10
An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of network packets can lead to authentication bypass and denial of service. An attacker can sen…
- CVE-2022-42233CRITICALCVSS 9.8EG 9.82022-10-20
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
- CVE-2022-42453MEDIUMCVSS 6.9EG 6.92022-12-19
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.
- CVE-2022-42458CRITICALCVSS 9.8EG 9.82022-12-07
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a …
- CVE-2022-42463HIGHCVSS 8.3EG 8.82022-10-14
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm …
- CVE-2022-42488HIGHCVSS 8.4EG 8.42022-10-14
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable securit…
- CVE-2022-4287HIGHCVSS 8.8EG 8.82022-12-21
Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malicious user to access the application.
- CVE-2022-42951HIGHCVSS 8.1EG 8.12023-02-06
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authenticati…
- CVE-2022-43400CRITICALCVSS 9.8EG 9.82022-10-21
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of…
- CVE-2022-43451HIGHCVSS 8.4EG 8.42022-11-03
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it …
- CVE-2022-43504MEDIUMCVSS 5.3EG 5.32022-12-05
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also pro…
- CVE-2022-43528MEDIUMCVSS 4.8EG 6.52023-01-05
Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a username and password a…
- CVE-2022-43549CRITICALCVSS 9.8EG 9.82022-12-05
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
- CVE-2022-43557MEDIUMCVSS 5.3EG 5.32022-12-05
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump.…
- CVE-2022-43620HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hand…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →