← Back
CWE-287

4,489 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,489)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nadatel
18At 0402e Firmware
At 0402l FirmwareAt 0402m Firmware+15 more
Jun 17, 2026
Dec 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
1Prolion
1Cryptospike
Jun 17, 2026
Dec 12, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and...Show more
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Apache Kafka (as consumer and producer).Show less
1Goodix
1Fingerprint Sensor Firmware
Jun 17, 2026
Dec 9, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to selec...Show more
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows template database, which allows bypass of Windows Hello authentication by enrolling an attacker's fingerprint.Show less
5Apple
CanonicalDebian+2 more
7Android
Debian LinuxFedora+4 more
Jun 17, 2026
Dec 8, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages w...Show more
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.Show less
1Zultys
6Mx E Firmware
Mx Se FirmwareMx Se Ii Firmware+3 more
Jun 17, 2026
Dec 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrati...Show more
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the authentication function. In normal operation, the Zultys MX Administrator Windows client connects to port 7505 and attempts authentication, submitting the administrator username and password to the server. Upon authentication failure, the server sends a login failure message prompting the client to disconnect. However, if the client ignores the failure message instead and attempts to continue, the server does not forcibly close the connection and processes all subsequent requests from the client as if authentication had been successful.Show less
1Prolion
1Cryptospike
Jun 17, 2026
Dec 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with differe...Show more
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.Show less
1Huawei
1Ajmd 370s Firmware
Jun 17, 2026
Dec 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.  Successf...Show more
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.  Successful exploitation of this vulnerability may allow attackers to access restricted functions. Show less
1Sonicwall
5Sma 200 Firmware
Sma 210 FirmwareSma 400 Firmware+2 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
1Vonage
1Vdv23 Firmware
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.
1Samsung
1Pass
Jun 17, 2026
Dec 5, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.
1Qualcomm
102Apq5053 Aa Firmware
Aqt1000 FirmwareAr8031 Firmware+99 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
1Qualcomm
167315 5g Iot Modem Firmware
8098 Firmware8998 Firmware+164 more
Jun 17, 2026
Dec 5, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
1Hitachi
1Vantara Hitachi Network Attached Storage
Jun 17, 2026
Dec 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and dia...Show more
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.Show less
1Dell
1Powerprotect Data Manager Dm5500 Firmware
Jun 17, 2026
Dec 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access of resources or functionality that could pos...Show more
Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access of resources or functionality that could possibly lead to execute arbitrary code. Show less
1Tylertech
1Court Case Management Plus
Jun 17, 2026
Nov 30, 2023
N/A· v4
9.4 CRITICAL· v3
N/A· v2
Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.
1Tylertech
1Court Case Management Plus
Jun 17, 2026
Nov 30, 2023
N/A· v4
9.4 CRITICAL· v3
N/A· v2
Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.
1Tylertech
1Court Case Management Plus
Jun 17, 2026
Nov 30, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a...Show more
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is related to or partially caused by CVE-2023-6352. Show less
1Tylertech
1Court Case Management Plus
Jun 17, 2026
Nov 30, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use...Show more
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is similar to CVE-2020-9323. CVE-2023-6343 is related to or partially caused by CVE-2023-6352. Show less
1Tylertech
1Court Case Management Plus
Jun 17, 2026
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters...Show more
Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" feature was removed on or around 2023-11-01.Show less