CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 70 of 99
- CVE-2023-28503CRITICALCVSS 9.8EG 9.82023-03-29
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can…
- CVE-2023-28540CRITICALCVSS 9.1EG 9.12023-10-03
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
- CVE-2023-28609CRITICALCVSS 9.8EG 9.82023-03-18
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
- CVE-2023-28646MEDIUMCVSS 4.4EG 4.42023-03-30
Nextcloud android is an android app for interfacing with the nextcloud home server ecosystem. In versions from 3.7.0 and before 3.24.1 an attacker that has access to the unlocked physical device can bypass the Nextcloud Android Pin/passcod…
- CVE-2023-28647MEDIUMCVSS 4.4EG 4.42023-03-30
Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.0 when an attacker has physical access to an unlocked device, they may enable the integration into the iOS Files app an…
- CVE-2023-28727CRITICALCVSS 9.6EG 9.62023-03-31
Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers.
- CVE-2023-28862CRITICALCVSS 9.8EG 9.82023-03-31
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny se…
- CVE-2023-28962MEDIUMCVSS 5.3EG 5.32023-04-17
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issu…
- CVE-2023-28963MEDIUMCVSS 5.3EG 5.32023-04-17
An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue …
- CVE-2023-28973HIGHCVSS 7.1EG 7.12023-04-17
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system…
- CVE-2023-29032HIGHCVSS 8.1EG 8.12023-05-12
An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0
- CVE-2023-29062LOWCVSS 3.8EG 3.82023-11-28
The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use …
- CVE-2023-29117HIGHCVSS 8.8EG 8.82024-11-05
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
- CVE-2023-29129CRITICALCVSS 9.1EG 9.12023-06-13
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 …
- CVE-2023-29155CRITICALCVSS 9.8EG 9.82023-11-20
Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could allow an attacker to obtain admin-level access to the host system.
- CVE-2023-29463HIGHCVSS 8.8EG 8.82023-09-12
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session data and or log use…
- CVE-2023-2959HIGHCVSS 7.5EG 8.22023-07-17
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.
- CVE-2023-2975MEDIUMCVSS 5.3EG 5.32023-07-14
Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to aut…
- CVE-2023-29975HIGHCVSS 7.2EG 7.22023-11-09
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
- CVE-2023-30061HIGHCVSS 7.5EG 7.52023-05-01
D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
- CVE-2023-30063HIGHCVSS 7.5EG 7.52023-05-01
D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.
- CVE-2023-30223HIGHCVSS 7.5EG 7.52023-06-16
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.
- CVE-2023-3028HIGHCVSS 8.6EG 8.62023-06-01
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected to…
- CVE-2023-30328CRITICALCVSS 9.8EG 9.82023-05-04
An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.
- CVE-2023-30559MEDIUMCVSS 5.2EG 5.22023-07-13
The firmware update package for the wireless card is not properly signed and can be modified.
- CVE-2023-30560MEDIUMCVSS 6.8EG 6.82023-07-13
The configuration from the PCU can be modified without authentication using physical connection to the PCU.
- CVE-2023-30603CRITICALCVSS 9.8EG 9.82023-06-02
Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. An unauthenticated remote attackers can exploit this vulnerabil…
- CVE-2023-3065CRITICALCVSS 9.1EG 9.12023-06-05
Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
- CVE-2023-30675MEDIUMCVSS 6.2EG 6.22023-07-06
Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.
- CVE-2023-3069CRITICALCVSS 9.8EG 9.82023-06-02
Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.
- CVE-2023-30700MEDIUMCVSS 5.3EG 5.32023-08-10
PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
- CVE-2023-30708MEDIUMCVSS 4.6EG 4.62023-09-06
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.
- CVE-2023-30711MEDIUMCVSS 4.0EG 4.02023-09-06
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
- CVE-2023-30724MEDIUMCVSS 4.0EG 4.02023-09-06
Improper authentication in GallerySearchProvider of Gallery prior to version 14.5.01.2 allows attacker to access search history.
- CVE-2023-30725MEDIUMCVSS 5.1EG 5.12023-09-06
Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider.
- CVE-2023-30762CRITICALCVSS 9.8EG 9.82023-06-13
Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versi…
- CVE-2023-30845HIGHCVSS 8.2EG 8.22023-04-26
ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authentication bypass vulnerability. API clients can craft a malicious `X-HTTP-Method-Override`…
- CVE-2023-30869CRITICALCVSS 9.8EG 9.82023-05-02
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.
- CVE-2023-30945CRITICALCVSS 9.8EG 9.82023-06-26
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A m…
- CVE-2023-30967CRITICALCVSS 9.8EG 9.82023-10-26
Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.
- CVE-2023-31007UnratedEG not assessed2023-07-12
Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authentication data expires if the client connected through the Pulsar Proxy when the broker is co…
- CVE-2023-31015MEDIUMCVSS 6.6EG 6.62023-09-20
NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, code ex…
- CVE-2023-31123CRITICALCVSS 9.1EG 9.12023-05-08
`effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior to commit bd80ba833b9023d39ca22e29874296c8729dd53b, any user with an account on an instance of `effectindex/tripreporter…
- CVE-2023-31127CRITICALCVSS 9.0EG 9.02023-05-08
libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPDM session establishment in libspdm prior to version 2.3.1. If a device supports both DHE session and PSK session with m…
- CVE-2023-31152MEDIUMCVSS 4.0EG 4.02023-05-10
An Authentication Bypass Using an Alternate Path or Channel vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface allows Authentication Bypass. See SEL Service Bulletin dated 202…
- CVE-2023-31189HIGHCVSS 5.2EG 8.82024-02-14
Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access.
- CVE-2023-31190HIGHCVSS 8.1EG 8.12023-07-11
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure. Specifically, the firmware update procedure ignores and does not check the validi…
- CVE-2023-31224CRITICALCVSS 9.8EG 9.82023-12-25
There is broken access control during authentication in Jamf Pro Server before 10.46.1.
- CVE-2023-31242HIGHCVSS 8.1EG 8.12023-09-05
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a…
- CVE-2023-3127HIGHCVSS 7.5EG 7.52023-07-11
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →