CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,940 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 72 of 99
- CVE-2023-3638CRITICALCVSS 9.8EG 9.82023-07-19
In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.
- CVE-2023-36466LOWCVSS 3.5EG 3.52023-07-14
Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The i…
- CVE-2023-36648HIGHCVSS 8.2EG 8.22023-12-12
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Ap…
- CVE-2023-36655CRITICALCVSS 9.8EG 9.82023-12-06
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowerc…
- CVE-2023-36724MEDIUMCVSS 5.5EG 5.52023-10-10
Windows Power Management Service Information Disclosure Vulnerability
- CVE-2023-36815HIGHCVSS 7.3EG 7.32023-07-03
Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.]…
- CVE-2023-36926LOWCVSS 3.7EG 3.72023-08-08
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather som…
- CVE-2023-37226CRITICALCVSS 9.8EG 9.82024-09-10
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
- CVE-2023-37266CRITICALCVSS 9.8EG 9.82023-07-17
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addre…
- CVE-2023-37268MEDIUMCVSS 6.4EG 6.42023-07-14
Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user with SSO enabled an attacker may authenticate as an other user. Any user account which does not have a second facto…
- CVE-2023-37283HIGHCVSS 8.1EG 8.12023-10-25
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
- CVE-2023-37284HIGHCVSS 8.8EG 8.82023-09-06
Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication.
- CVE-2023-37362HIGHCVSS 7.2EG 7.22023-07-19
Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.
- CVE-2023-37471CRITICALCVSS 9.1EG 9.12023-07-20
Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of …
- CVE-2023-37544HIGHCVSS 7.5EG 7.52023-12-20
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 …
- CVE-2023-37918MEDIUMCVSS 6.8EG 6.82023-07-21
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability has been found in Dapr that allows bypassing API token authentication, which is used by the Dapr sidecar to authenticate…
- CVE-2023-38096CRITICALCVSS 9.8EG 9.82024-05-03
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System.…
- CVE-2023-38367MEDIUMCVSS 6.5EG 6.52024-02-29
IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with a…
- CVE-2023-38372MEDIUMCVSS 5.9EG 5.92024-02-29
An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM X-Force ID: 261201.
- CVE-2023-38534HIGHCVSS 8.6EG 8.62024-03-13
Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC.
- CVE-2023-38555HIGHCVSS 8.8EG 8.82023-07-26
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected product…
- CVE-2023-38585HIGHCVSS 8.8EG 8.82023-08-23
Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information pr…
- CVE-2023-38691MEDIUMCVSS 5.0EG 5.02023-08-04
matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user's MXID in an OpenID exchange, allowing a bad actor to impers…
- CVE-2023-38735MEDIUMCVSS 5.7EG 5.72023-10-22
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. I…
- CVE-2023-39069CRITICALCVSS 9.8EG 9.82023-09-11
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.
- CVE-2023-39112MEDIUMCVSS 6.5EG 6.52023-08-04
ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.
- CVE-2023-39196MEDIUMCVSS 5.3EG 5.32024-02-07
Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container Manager service without proper authentication. The attacker is not allowed to do any modifi…
- CVE-2023-39215HIGHCVSS 7.1EG 7.12023-09-12
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
- CVE-2023-39303MEDIUMCVSS 5.3EG 5.32024-02-02
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed t…
- CVE-2023-39345HIGHCVSS 7.6EG 7.62023-11-06
strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user record…
- CVE-2023-39349HIGHCVSS 8.1EG 8.12023-08-07
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens creat…
- CVE-2023-39380HIGHCVSS 7.5EG 7.52023-08-13
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.
- CVE-2023-39415HIGHCVSS 7.5EG 7.52023-08-18
Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to…
- CVE-2023-39531MEDIUMCVSS 6.5EG 6.52023-08-09
Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2, an attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth…
- CVE-2023-39846CRITICALCVSS 9.8EG 9.82023-08-16
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
- CVE-2023-39981HIGHCVSS 7.5EG 7.52023-09-02
A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information …
- CVE-2023-40020CRITICALCVSS 9.9EG 9.92023-08-14
PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Le…
- CVE-2023-40038HIGHCVSS 8.8EG 8.82023-12-27
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)
- CVE-2023-40253MEDIUMCVSS 6.0EG 6.02023-08-11
Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Authentication Abuse.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Gen…
- CVE-2023-40260CRITICALCVSS 9.1EG 9.12023-08-11
EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's email address, and…
- CVE-2023-40282MEDIUMCVSS 5.4EG 5.42023-08-23
Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be change…
- CVE-2023-40376MEDIUMCVSS 5.3EG 5.32023-10-04
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X…
- CVE-2023-40660MEDIUMCVSS 6.6EG 6.62023-11-06
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses …
- CVE-2023-4094HIGHCVSS 8.2EG 8.22023-09-19
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified t…
- CVE-2023-41089HIGHCVSS 8.8EG 8.82023-10-19
The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long as the device keeps the session active, since the attack takes advantage of the c…
- CVE-2023-41261MEDIUMCVSS 5.3EG 5.32023-10-12
An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not require authentication and allows an unauthenticated user to export a report and access the resu…
- CVE-2023-41264CRITICALCVSS 9.8EG 9.82023-11-28
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettin…
- CVE-2023-41442CRITICALCVSS 9.8EG 9.82023-11-15
An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted request to the MQTT component.
- CVE-2023-41751MEDIUMCVSS 5.5EG 6.32023-08-31
Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before build 32047.
- CVE-2023-41900MEDIUMCVSS 4.3EG 4.32023-09-15
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginServi…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →