CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 69 of 99
- CVE-2023-25556HIGHCVSS 8.3EG 8.32023-04-18
A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.
- CVE-2023-25559HIGHCVSS 8.2EG 8.22023-02-11
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-DataHub-Actor HTTP header to infer the user the frontend is …
- CVE-2023-25597MEDIUMCVSS 5.9EG 5.92023-04-14
A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentic…
- CVE-2023-25601MEDIUMCVSS 4.3EG 4.32023-04-20
On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For u…
- CVE-2023-25790MEDIUMCVSS 5.3EG 5.32024-04-24
Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart allows Cross-Site Scripting (XSS).This issue affects WoodMart: from n/a through 7.0.4.
- CVE-2023-2586CRITICALCVSS 9.0EG 9.02023-05-22
Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by de…
- CVE-2023-25913HIGHCVSS 7.5EG 7.72023-08-21
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.
- CVE-2023-25931MEDIUMCVSS 6.4EG 6.82023-03-01
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthori…
- CVE-2023-25946HIGHCVSS 8.8EG 8.82023-05-23
Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product's communication data and conduct an arbitrary operation under certain conditions.
- CVE-2023-25957CRITICALCVSS 9.1EG 9.12023-03-14
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All ver…
- CVE-2023-26150MEDIUMCVSS 6.5EG 6.52023-10-03
Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for servic…
- CVE-2023-2626HIGHCVSS 7.5EG 7.52023-07-25
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption…
- CVE-2023-2638MEDIUMCVSS 5.9EG 5.92023-06-13
Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected. Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.…
- CVE-2023-26455MEDIUMCVSS 5.6EG 5.62023-11-02
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by…
- CVE-2023-26570HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.
- CVE-2023-26571HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers.
- CVE-2023-26573HIGHCVSS 8.2EG 8.22023-10-25
Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.
- CVE-2023-26574HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.
- CVE-2023-26575HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.
- CVE-2023-26576HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.
- CVE-2023-2706HIGHCVSS 8.1EG 8.12023-05-17
The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these cod…
- CVE-2023-27091HIGHCVSS 7.2EG 7.22023-04-04
An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).
- CVE-2023-27256MEDIUMCVSS 5.8EG 5.82023-10-25
Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of sensitive log files by unauthenticated attackers.
- CVE-2023-27257HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student information by unauthenticated attackers.
- CVE-2023-27258HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.
- CVE-2023-27259HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.
- CVE-2023-27261MEDIUMCVSS 5.3EG 5.32023-10-25
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers.
- CVE-2023-27351CRITICALCVSS 7.5EG 9.0⚠ KEV2023-04-20
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRe…
- CVE-2023-27375HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- CVE-2023-27376HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- CVE-2023-27377HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- CVE-2023-27388CRITICALCVSS 9.8EG 9.82023-05-23
Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Cor…
- CVE-2023-27482CRITICALCVSS 10.0EG 10.02023-03-08
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation t…
- CVE-2023-27535HIGHCVSS 5.9EG 7.52023-03-30
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool f…
- CVE-2023-27536CRITICALCVSS 5.9EG 9.82023-03-30
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DEL…
- CVE-2023-27538MEDIUMCVSS 5.5EG 5.52023-03-30
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool …
- CVE-2023-27582CRITICALCVSS 9.1EG 9.12023-03-13
maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. In…
- CVE-2023-2759HIGHCVSS 8.8EG 8.82023-07-17
A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may gain full access to the device by using…
- CVE-2023-27823CRITICALCVSS 9.8EG 9.82023-05-12
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
- CVE-2023-27877MEDIUMCVSS 5.3EG 5.32023-07-19
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 2479…
- CVE-2023-27919MEDIUMCVSS 5.3EG 5.32023-05-10
Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.
- CVE-2023-28073HIGHCVSS 8.2EG 8.22023-06-23
Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability by bypassing certain authentication mechanisms in order to elevate privileges on the system.
- CVE-2023-28121CRITICALCVSS 9.8EG 9.82023-04-12
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain …
- CVE-2023-28125MEDIUMCVSS 5.9EG 5.92023-05-09
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
- CVE-2023-28182MEDIUMCVSS 6.5EG 6.52023-05-08
The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A user in a privileged network position m…
- CVE-2023-28325MEDIUMCVSS 6.5EG 6.52023-05-11
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target roo…
- CVE-2023-28377MEDIUMCVSS 6.7EG 6.72023-11-14
Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28398CRITICALCVSS 9.8EG 9.82023-03-28
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user acc…
- CVE-2023-28461CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-15
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could t…
- CVE-2023-28473LOWCVSS 3.3EG 3.32023-04-28
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →