CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,940 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 71 of 99
- CVE-2023-31279HIGHCVSS 8.1EG 8.12024-12-21
The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage Management Service on the devices or registered the d…
- CVE-2023-31292MEDIUMCVSS 5.5EG 5.52023-12-29
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.
- CVE-2023-31634CRITICALCVSS 9.8EG 9.82024-03-27
In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for re…
- CVE-2023-32081MEDIUMCVSS 6.5EG 6.52023-05-12
Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.0 until 4.4.2, a Vert.x STOMP server processes client STOMP frames without checking that t…
- CVE-2023-32090CRITICALCVSS 9.8EG 9.82023-08-07
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
- CVE-2023-32202MEDIUMCVSS 6.5EG 6.52023-08-23
Walchem Intuition 9 firmware versions prior to v4.21 are vulnerable to improper authentication. Login credentials are stored in a format that could allow an attacker to use them as-is to login and gain access to the device.
- CVE-2023-32220HIGHCVSS 8.2EG 8.22023-06-12
Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
- CVE-2023-32222CRITICALCVSS 9.8EG 9.82023-06-28
D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.
- CVE-2023-32243CRITICALCVSS 9.8EG 9.82023-05-12
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
- CVE-2023-32347HIGHCVSS 8.1EG 8.12023-05-22
Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the user perspective for device claiming and from the device perspective for authentication. If an attack…
- CVE-2023-32453MEDIUMCVSS 4.6EG 4.62023-08-16
Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit this vulnerability in order to modify a security-critical UEFI variable without knowledge of the BIOS…
- CVE-2023-32523HIGHCVSS 8.8EG 8.82023-06-26
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obt…
- CVE-2023-32524HIGHCVSS 8.8EG 8.82023-06-26
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obt…
- CVE-2023-32620MEDIUMCVSS 6.5EG 6.52023-06-30
Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attacker to obtain a password for the wireless network.
- CVE-2023-3263HIGHCVSS 7.5EG 7.52023-08-14
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malic…
- CVE-2023-32661MEDIUMCVSS 6.7EG 6.72023-11-14
Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.19041.29098 may allow an authenticated user to potentially enable escalation of privilege via …
- CVE-2023-32682MEDIUMCVSS 5.4EG 5.42023-06-06
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon configurations. This only applies if any of the following are…
- CVE-2023-33054CRITICALCVSS 9.1EG 9.12023-12-05
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
- CVE-2023-33070HIGHCVSS 7.1EG 7.12023-12-05
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
- CVE-2023-33190CRITICALCVSS 9.9EG 9.92023-06-29
Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper configuration of role based access control (RBAC) permissions resulted in an attacker being a…
- CVE-2023-33237HIGHCVSS 8.8EG 8.82023-08-17
TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-privileged APIs to ex…
- CVE-2023-3326CRITICALCVSS 9.8EG 9.82023-06-22
pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is…
- CVE-2023-33274CRITICALCVSS 9.8EG 9.82023-07-12
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerab…
- CVE-2023-33363HIGHCVSS 7.5EG 7.52023-08-03
An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers.
- CVE-2023-3337HIGHCVSS 7.3EG 7.32023-06-20
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. T…
- CVE-2023-33553CRITICALCVSS 9.8EG 9.82023-06-07
An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie.
- CVE-2023-33563HIGHCVSS 8.8EG 8.82023-08-01
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- CVE-2023-3362MEDIUMCVSS 5.3EG 5.32023-07-13
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
- CVE-2023-34124CRITICALCVSS 9.8EG 9.82023-07-13
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
- CVE-2023-34137CRITICALCVSS 9.8EG 9.82023-07-13
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass vulnerability. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-…
- CVE-2023-34196HIGHCVSS 8.2EG 8.22023-08-03
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and p…
- CVE-2023-34246MEDIUMCVSS 4.2EG 4.22023-06-12
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inh…
- CVE-2023-34340CRITICALCVSS 9.8EG 9.82023-06-21
Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials …
- CVE-2023-34367MEDIUMCVSS 6.5EG 6.52023-06-14
Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devic…
- CVE-2023-34388MEDIUMCVSS 6.5EG 6.52023-11-30
An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instructio…
- CVE-2023-3470MEDIUMCVSS 6.0EG 6.02023-08-02
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or …
- CVE-2023-34998HIGHCVSS 8.1EG 8.12023-09-05
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff …
- CVE-2023-35078CRITICALCVSS 9.8EG 10.0⚠ KEV2023-07-25
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
- CVE-2023-35082CRITICALCVSS 9.8EG 10.0⚠ KEV2023-08-15
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-350…
- CVE-2023-35137HIGHCVSS 7.5EG 7.52023-11-30
An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain system information b…
- CVE-2023-35154HIGHCVSS 7.2EG 7.22023-06-23
Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allow…
- CVE-2023-35785CRITICALCVSS 8.1EG 9.82023-08-28
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 …
- CVE-2023-35794HIGHCVSS 8.8EG 8.82023-10-27
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; ins…
- CVE-2023-35874MEDIUMCVSS 6.0EG 6.02023-07-11
SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.5…
- CVE-2023-35901LOWCVSS 2.7EG 2.72023-07-17
IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380.
- CVE-2023-3591MEDIUMCVSS 4.8EG 4.82023-07-17
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
- CVE-2023-35940HIGHCVSS 7.5EG 7.52023-07-05
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contain…
- CVE-2023-3597MEDIUMCVSS 5.0EG 5.02024-04-25
A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication fac…
- CVE-2023-36004HIGHCVSS 7.5EG 7.52023-12-12
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
- CVE-2023-3622MEDIUMCVSS 4.3EG 4.62023-07-26
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →