CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 66 of 99
- CVE-2022-43690MEDIUMCVSS 6.3EG 6.32022-11-14
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authentication bypass could occur if using this functionality. Remediate by updating to Concrete C…
- CVE-2022-43782CRITICALCVSS 9.8EG 9.82022-11-17
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. Thi…
- CVE-2022-43900MEDIUMCVSS 5.3EG 6.52022-12-01
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827.
- CVE-2022-43978MEDIUMCVSS 5.6EG 5.62023-01-27
There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker w…
- CVE-2022-44013CRITICALCVSS 9.1EG 9.12022-12-25
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authentication because the password in a Credential Object is not checked.
- CVE-2022-44022MEDIUMCVSS 5.3EG 5.32022-10-30
PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts.
- CVE-2022-44037HIGHCVSS 8.8EG 8.82022-11-29
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attackers to access sensitive data and execute specific commands and functions with full admin ri…
- CVE-2022-44244MEDIUMCVSS 6.6EG 6.62022-11-09
An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.
- CVE-2022-4441HIGHCVSS 7.6EG 8.82023-01-31
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 0…
- CVE-2022-44569HIGHCVSS 7.8EG 8.82023-11-03
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
- CVE-2022-44574HIGHCVSS 7.5EG 8.42023-03-10
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port.
- CVE-2022-44595MEDIUMCVSS 5.3EG 5.32024-03-21
Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.
- CVE-2022-44610MEDIUMCVSS 5.4EG 5.42023-05-10
Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.
- CVE-2022-44620HIGHCVSS 8.8EG 8.82022-12-07
Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- CVE-2022-44801CRITICALCVSS 9.8EG 9.82022-11-22
D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
- CVE-2022-45118MEDIUMCVSS 6.2EG 6.22022-12-08
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information …
- CVE-2022-45124HIGHCVSS 7.5EG 7.52023-03-20
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can sniff ne…
- CVE-2022-45168MEDIUMCVSS 6.5EG 6.52024-06-10
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application…
- CVE-2022-45173CRITICALCVSS 9.8EG 9.82023-04-14
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successfu…
- CVE-2022-45174CRITICALCVSS 9.8EG 9.82023-04-14
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness …
- CVE-2022-45378CRITICALCVSS 9.8EG 9.82022-11-14
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are avail…
- CVE-2022-45430LOWCVSS 3.7EG 3.72022-12-27
Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could en…
- CVE-2022-45431HIGHCVSS 7.5EG 7.52022-12-27
Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unau…
- CVE-2022-45432MEDIUMCVSS 5.3EG 5.32022-12-27
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticate…
- CVE-2022-45433LOWCVSS 3.7EG 3.72022-12-27
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker …
- CVE-2022-45434MEDIUMCVSS 5.9EG 5.92022-12-27
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an …
- CVE-2022-45456HIGHCVSS 7.5EG 7.52023-04-26
Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161.
- CVE-2022-45724MEDIUMCVSS 5.4EG 5.42023-02-13
Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an att…
- CVE-2022-45860MEDIUMCVSS 5.3EG 5.32023-05-03
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated a…
- CVE-2022-45877HIGHCVSS 8.3EG 8.32022-12-08
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
- CVE-2022-45922HIGHCVSS 8.8EG 8.82023-01-18
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, whi…
- CVE-2022-45933CRITICALCVSS 9.8EG 9.82022-11-27
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the…
- CVE-2022-46145HIGHCVSS 8.1EG 8.12022-12-02
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in …
- CVE-2022-46146MEDIUMCVSS 6.2EG 6.22022-11-29
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in au…
- CVE-2022-46170HIGHCVSS 8.6EG 8.62022-12-22
CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHa…
- CVE-2022-46172MEDIUMCVSS 6.4EG 6.42022-12-28
authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would ci…
- CVE-2022-46313MEDIUMCVSS 5.3EG 5.32022-12-20
The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.
- CVE-2022-46316CRITICALCVSS 9.8EG 9.82022-12-20
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
- CVE-2022-46400MEDIUMCVSS 5.4EG 5.42022-12-19
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
- CVE-2022-46411HIGHCVSS 8.8EG 8.82022-12-04
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
- CVE-2022-46773MEDIUMCVSS 4.3EG 6.52023-03-15
IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.
- CVE-2022-46774MEDIUMCVSS 5.4EG 6.52023-03-15
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.
- CVE-2022-46829HIGHCVSS 7.1EG 8.82022-12-08
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
- CVE-2022-46875MEDIUMCVSS 6.5EG 6.52022-12-22
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. T…
- CVE-2022-4693CRITICALCVSS 9.8EG 9.82023-01-23
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily quer…
- CVE-2022-47003CRITICALCVSS 9.8EG 9.82023-02-01
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
- CVE-2022-47209HIGHCVSS 8.8EG 8.82022-12-16
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.
- CVE-2022-4722HIGHCVSS 7.2EG 7.22022-12-27
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- CVE-2022-47408CRITICALCVSS 9.1EG 9.12022-12-14
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribin…
- CVE-2022-47508HIGHCVSS 7.5EG 7.52023-02-15
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →