← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dahuasecurity
19Ipc Hum7xxx Firmware
Ipc Hx3xxx FirmwareIpc Hx5xxx Firmware+16 more
Jun 17, 2026
Sep 15, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
1Sap
1Business One
Jun 17, 2026
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sens...Show more
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take substantial control of the vulnerable application.Show less
18x8
1Jitsi Meet
Jun 17, 2026
Sep 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbit...Show more
Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected rooms. This issue is fixed in Jitsi Meet 2.0.5963. There are no known workarounds aside from updating.Show less
1Ionic
1Identity Vault
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Sep 10, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
1Samsung
1Internet
Jun 17, 2026
Sep 9, 2021
N/A· v4
5.9 MEDIUM· v3
5.0 MEDIUM· v2
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
1Google
1Android
Jun 17, 2026
Sep 9, 2021
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
1Openbmc Project
1Openbmc
Jun 17, 2026
Sep 9, 2021
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x trainShow less
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affect...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releasesShow less
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue af...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior releasesShow less
1Cisco
1Broadworks Commpilot Application Software
Jun 17, 2026
Sep 9, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
1Cisco
1Broadworks Commpilot Application Software
Jun 17, 2026
Sep 9, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
1Google
1Chrome Os Readiness Tool
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
1Apple
2Mac Os X
Macos
Jun 17, 2026
Sep 8, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A person with physical access to a Mac may be abl...Show more
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A person with physical access to a Mac may be able to bypass Login Window.Show less
1Apple
1Macos
Jun 17, 2026
Sep 8, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A person with physical access to a Mac may be able to bypass Login Window during a software update.
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.4 MEDIUM· v3
4.8 MEDIUM· v2
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force a client to use a less secure authentication mechanism.
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 8, 2021
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an i...Show more
An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone number.Show less
1Apple
3Iphone Os
TvosWatchos
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
1Apple
3Iphone Os
TvosWatchos
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authenticat...Show more
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.Show less