CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 67 of 99
- CVE-2022-47633HIGHCVSS 8.1EG 8.12022-12-23
An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fi…
- CVE-2022-47700HIGHCVSS 7.5EG 7.52023-01-31
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect Access Control. Improper authentication allows requests to be made to back-end scripts without a valid …
- CVE-2022-4779CRITICALCVSS 7.5EG 9.82022-12-29
StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web server feature activate…
- CVE-2022-47848HIGHCVSS 7.5EG 7.52023-09-15
An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml …
- CVE-2022-47974MEDIUMCVSS 6.5EG 6.52023-01-06
The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth process to restart.
- CVE-2022-47976HIGHCVSS 7.5EG 7.52023-01-06
The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.
- CVE-2022-48066CRITICALCVSS 9.8EG 9.82023-01-27
An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.
- CVE-2022-48195CRITICALCVSS 9.8EG 9.82022-12-31
An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty). This ca…
- CVE-2022-48254MEDIUMCVSS 4.6EG 4.62023-02-27
There is a data processing error vulnerability in Leia-B29 2.0.0.49(M03). Successful exploitation could bypass lock screen authentication.
- CVE-2022-48294HIGHCVSS 7.5EG 7.52023-02-09
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-48305MEDIUMCVSS 5.5EG 5.52023-02-27
There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail.
- CVE-2022-48314MEDIUMCVSS 6.5EG 6.52023-04-16
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2022-48364MEDIUMCVSS 4.3EG 4.32023-03-06
The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does not use the server's representative account, resulting in moderator identity disclosure when a moderator approves the …
- CVE-2022-48494HIGHCVSS 7.5EG 7.52023-06-19
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
- CVE-2022-48496HIGHCVSS 7.5EG 7.52023-06-19
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
- CVE-2022-48575LOWCVSS 3.5EG 3.52026-06-10
A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.
- CVE-2022-4861MEDIUMCVSS 4.8EG 4.92022-12-30
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
- CVE-2022-48618CRITICALCVSS 7.0EG 9.0⚠ KEV2024-01-09
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. A…
- CVE-2022-4874HIGHCVSS 7.5EG 7.52023-01-11
Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the …
- CVE-2023-0035HIGHCVSS 6.5EG 7.82023-01-09
softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with hi…
- CVE-2023-0036HIGHCVSS 6.5EG 7.82023-01-09
platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high pri…
- CVE-2023-0105MEDIUMCVSS 6.5EG 6.52023-01-13
A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate them.
- CVE-2023-0117MEDIUMCVSS 5.3EG 5.32023-05-26
The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime.
- CVE-2023-0209HIGHCVSS 8.2EG 8.22023-04-22
NVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA is missing, which may lead to arbitrary code execution, denial of service, escalation of privileges assisted by a firmwa…
- CVE-2023-0228HIGHCVSS 8.8EG 8.82023-03-02
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
- CVE-2023-0264MEDIUMCVSS 5.0EG 5.02023-08-04
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to imperson…
- CVE-2023-0311CRITICALCVSS 9.8EG 9.82023-01-15
Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- CVE-2023-0346HIGHCVSS 7.5EG 7.52023-03-13
Akuvox E11 cloud login is performed through an unencrypted HTTP connection. An attacker could gain access to the Akuvox cloud and device if the MAC address of a device if known.
- CVE-2023-0773CRITICALCVSS 9.1EG 9.12023-09-19
The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vuln…
- CVE-2023-0813HIGHCVSS 7.5EG 8.62023-09-15
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in…
- CVE-2023-0858LOWCVSS 3.1EG 3.12023-05-11
Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Ser…
- CVE-2023-0863HIGHCVSS 8.8EG 8.82023-05-17
Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra…
- CVE-2023-0905HIGHCVSS 7.3EG 7.52023-02-18
A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It i…
- CVE-2023-1065MEDIUMCVSS 6.5EG 6.52023-02-28
This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expose the user of the integration to any dire…
- CVE-2023-1327CRITICALCVSS 9.8EG 9.82023-03-14
Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin p…
- CVE-2023-1460CRITICALCVSS 6.5EG 9.82023-03-17
A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=save_user of the component Password Change Handler. The manipu…
- CVE-2023-1464CRITICALCVSS 7.3EG 9.82023-03-17
A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file Users.php?f=save_user. The manipulation of the argument firstname/middlename/lastname/user…
- CVE-2023-1477HIGHCVSS 7.2EG 7.22023-04-28
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.
- CVE-2023-1617CRITICALCVSS 9.8EG 9.82023-04-14
Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on af…
- CVE-2023-1752HIGHCVSS 8.1EG 8.12023-04-04
The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associated device with only the device’s MAC address.
- CVE-2023-1778CRITICALCVSS 10.0EG 10.02023-04-27
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web…
- CVE-2023-1784CRITICALCVSS 5.3EG 9.82023-03-31
A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotel…
- CVE-2023-1803CRITICALCVSS 9.8EG 10.02023-04-14
Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17.
- CVE-2023-1833CRITICALCVSS 9.8EG 10.02023-04-14
Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17.
- CVE-2023-1935CRITICALCVSS 9.4EG 9.42023-08-02
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.
- CVE-2023-1980MEDIUMCVSS 6.5EG 6.52023-04-11
Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authentication via the application user interface and open entries.
- CVE-2023-20012MEDIUMCVSS 5.3EG 5.32023-02-23
A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentica…
- CVE-2023-20199MEDIUMCVSS 6.2EG 6.22023-06-28
A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication and access an affected macOS device. This vulnerability is due to the incorrect handling of…
- CVE-2023-20214CRITICALCVSS 9.1EG 9.12023-08-03
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an aff…
- CVE-2023-20238CRITICALCVSS 10.0EG 10.02023-09-06
A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required t…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →