CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authentication bypass could occur if using this functionality. Remediate by upd...Show more |
3Newsmag Project Newspaper ProjectTagdiv Composer Project3Newsmag NewspaperTagdiv ComposerJun 17, 2026 Nov 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenti...Show more |
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695. |
1Intel 8Nuc Kit Nuc5i3ryh Firmware Nuc Kit Nuc5i3ryhs FirmwareNuc Kit Nuc5i3ryhsn Firmware+5 moreJun 17, 2026 Nov 11, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 2Nuc Board Nuc5i3mybe Firmware Nuc Kit Nuc5i3myhe FirmwareJun 17, 2026 Nov 11, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Nov 11, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an authenticated user to potentially enable escalation of privilege via netwo...Show more |
Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access. |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Nov 11, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable escalation of privilege via net...Show more |
1Intel 1Server Debug And Provisioning Tool Jun 17, 2026 Nov 11, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access. |
1Intel 5Nuc 8 Business Nuc8i7hnkqc Firmware Nuc 8 Enthusiast Nuc8i7hvkva FirmwareNuc 8 Enthusiast Nuc8i7hvkvaw Firmware+2 moreJun 17, 2026 Nov 11, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation...Show more |
1Intel 1Active Management Technology Firmware Jun 17, 2026 Nov 11, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a privileged user to potentially enable escalation of privilege via local ac...Show more |
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate...Show more |
UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt s...Show more |
An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator. |
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature. |
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need...Show more |
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to au...Show more |
1Citrix 2Application Delivery Controller Firmware GatewayJun 17, 2026 Nov 8, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Unauthorized access to Gateway user capabilities
|
XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has an OpenID provider configured through its xwiki.properties, it is possible to provide a third party...Show more |
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other...Show more |