CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,940 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 73 of 99
- CVE-2023-41904MEDIUMCVSS 5.4EG 5.42023-09-27
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
- CVE-2023-41956HIGHCVSS 8.8EG 8.82024-05-17
Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.
- CVE-2023-41999CRITICALCVSS 9.8EG 9.82023-11-27
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that requir…
- CVE-2023-4242MEDIUMCVSS 4.3EG 4.32023-08-09
The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level pe…
- CVE-2023-42442HIGHCVSS 5.3EG 7.02023-09-15
JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, session replays can download without authentication. Session rep…
- CVE-2023-42531CRITICALCVSS 7.1EG 9.82023-11-07
Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.
- CVE-2023-42554MEDIUMCVSS 6.8EG 6.82023-11-07
Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.
- CVE-2023-42576MEDIUMCVSS 6.8EG 6.82023-12-05
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.
- CVE-2023-42662CRITICALCVSS 9.3EG 9.32024-03-07
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of…
- CVE-2023-42771HIGHCVSS 8.8EG 8.82023-10-03
Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuratio…
- CVE-2023-42818CRITICALCVSS 9.8EG 9.82023-09-27
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a discl…
- CVE-2023-42935MEDIUMCVSS 5.5EG 5.52024-01-23
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.
- CVE-2023-43551CRITICALCVSS 9.1EG 9.12024-06-03
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
- CVE-2023-43582HIGHCVSS 8.8EG 8.82023-11-15
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
- CVE-2023-43660HIGHCVSS 8.1EG 8.12023-09-27
Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be bypassed by sending an SSH key offer without a signature. This allows bypassing authenticatio…
- CVE-2023-4373CRITICALCVSS 9.8EG 9.82023-08-21
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote to…
- CVE-2023-43742CRITICALCVSS 9.8EG 9.82023-12-08
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a pr…
- CVE-2023-43793HIGHCVSS 7.5EG 7.52023-10-04
Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.…
- CVE-2023-43805HIGHCVSS 7.5EG 7.52023-10-04
Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete URL validation can allow users to bypass authentication for access to the job queue dashboard. Version 12.121.9 contain…
- CVE-2023-43809HIGHCVSS 7.5EG 7.52023-10-04
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to bypass public key authentication when keyboard-interactive SSH…
- CVE-2023-44039CRITICALCVSS 9.1EG 9.12024-04-03
In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register their FIDO authenticator to a victim’s account and consequen…
- CVE-2023-44096HIGHCVSS 7.5EG 7.52023-10-11
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-4415HIGHCVSS 8.8EG 8.92023-08-18
A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may…
- CVE-2023-44152CRITICALCVSS 9.1EG 9.12023-09-27
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- CVE-2023-44252HIGHCVSS 8.8EG 8.82023-12-13
** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or H…
- CVE-2023-44302CRITICALCVSS 9.8EG 9.82023-12-04
Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access of resources or functionality that could possibly lead to execu…
- CVE-2023-44324CRITICALCVSS 9.8EG 9.82023-11-17
Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the AP…
- CVE-2023-44397CRITICALCVSS 9.8EG 9.82023-10-30
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. V…
- CVE-2023-44752CRITICALCVSS 9.8EG 9.82025-04-22
An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.
- CVE-2023-4498MEDIUMCVSS 5.3EG 5.32023-09-06
Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to authenticated users only
- CVE-2023-4501CRITICALCVSS 9.8EG 9.82023-09-12
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versio…
- CVE-2023-45038MEDIUMCVSS 4.3EG 4.32024-09-06
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the f…
- CVE-2023-45246HIGHCVSS 7.1EG 7.12023-10-06
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36343, Acronis Cyber Protect 16 (Linux, macOS, Wind…
- CVE-2023-45249CRITICALCVSS 9.8EG 9.8⚠ KEV2024-07-24
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure…
- CVE-2023-4562CRITICALCVSS 9.1EG 9.12023-10-13
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper da…
- CVE-2023-45669MEDIUMCVSS 5.3EG 5.32023-10-16
WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions are subject to improper signature counter value handling. A flaw was found in webauthn4j-spring-security-core. When an …
- CVE-2023-4568MEDIUMCVSS 6.5EG 6.52023-09-13
PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.
- CVE-2023-45801HIGHCVSS 7.5EG 7.52023-12-13
Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.
- CVE-2023-45866HIGHCVSS 6.3EG 8.82023-12-08
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interac…
- CVE-2023-4612CRITICALCVSS 9.8EG 9.82023-11-09
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions…
- CVE-2023-46172MEDIUMCVSS 5.6EG 5.62024-03-07
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions for authorized user. IBM X-Force ID: 269409.
- CVE-2023-46249CRITICALCVSS 9.8EG 9.82023-10-31
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any aut…
- CVE-2023-46290HIGHCVSS 8.1EG 8.12023-10-27
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Ser…
- CVE-2023-46327MEDIUMCVSS 5.9EG 5.92023-11-02
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. W…
- CVE-2023-4641MEDIUMCVSS 5.5EG 5.52023-12-27
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an…
- CVE-2023-46630HIGHCVSS 7.5EG 7.52024-06-04
Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Admin and Site Enhancements (ASE): from n/a through 5.7.1.
- CVE-2023-4669CRITICALCVSS 9.8EG 9.82023-09-14
Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0.
- CVE-2023-46717HIGHCVSS 7.5EG 7.52024-03-12
An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write acce…
- CVE-2023-4677CRITICALCVSS 9.8EG 9.82023-11-23
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to aut…
- CVE-2023-46805CRITICALCVSS 8.2EG 9.0⚠ KEV2024-01-12
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →