← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Secure Email And Web Manager
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modi...Show more
A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user. This vulnerability exists because access to the spam quarantine feature is not properly restricted. An attacker could exploit this vulnerability by sending malicious requests to an affected system. A successful exploit could allow the attacker to modify another user's spam quarantine settings, possibly disabling security controls or viewing email messages stored on the spam quarantine interfaces.Show less
1Motorola
1Mm1000 Firmware
Jun 17, 2026
Aug 17, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.
1Cozmoslabs
1Profile Builder
Jun 17, 2026
Aug 16, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way th...Show more
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.Show less
1Microsoft
2Azure Active Directory Connect
Azure Active Directory Connect Provisioning Agent
Jun 17, 2026
Aug 12, 2021
N/A· v4
7.1 HIGH· v3
4.9 MEDIUM· v2
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
1Monitorapp
1Application Insight Manager
Jun 17, 2026
Aug 12, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an...Show more
AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has Improper Authentication. An attacker can gain administrative access by modifying the response to an authentication check request.Show less
1Broadcom
1Fabric Operating System
Jun 17, 2026
Aug 12, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, s...Show more
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a and v7.4.2h could allow a user to Login with empty password, and invalid password through telnet, ssh and REST.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Aug 11, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when th...Show more
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier than PAN-OS 10.0.5. PAN-OS 10.1 versions are not impacted.Show less
1Siemens
2Simatic S7 1200 Cpu Firmware
Simatic Step 7 (tia Portal)
Jun 17, 2026
Aug 10, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could all...Show more
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fail to authenticate against configured passwords when provisioned using TIA Portal V13. This could allow an attacker using TIA Portal V13 or later versions to bypass authentication and download arbitrary programs to the PLC. The vulnerability does not occur when TIA Portal V13 SP1 or any later version was used to provision the device.Show less
1Dell
1Openmanage Enterprise
Jun 17, 2026
Aug 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to hijack an elevated session or perform u...Show more
Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to hijack an elevated session or perform unauthorized actions by sending malformed data.Show less
1Sap
1Businessobjects Edge
Nov 21, 2024
Aug 9, 2021
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.
1Mitsubishielectric
8R08psfcpu Firmware
R08sfcpu FirmwareR120psfcpu Firmware+5 more
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacke...Show more
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to lockout a legitimate user by continuously trying login with incorrect password.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
1Acronis
1True Image
Jun 17, 2026
Aug 5, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service...Show more
Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service API.Show less
1Samsung
1Internet
Jun 17, 2026
Aug 5, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.
1Redhat
1Openshift
Jun 17, 2026
Jul 30, 2021
N/A· v4
4.6 MEDIUM· v3
4.1 MEDIUM· v2
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing t...Show more
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates signed by the trusted Service CA. The incorrect inclusion of additional CAs in this certificate would allow an attacker that compromises any of the additional CAs to masquerade as a trusted in-cluster service.Show less
1Crestron
3Dm Nvx Dir 160 Firmware
Dm Nvx Dir 80 FirmwareDm Nvx Dir Ent Firmware
Jun 17, 2026
Jul 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.
1Dell
1Idrac9 Firmware
Jun 17, 2026
Jul 29, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to t...Show more
Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the virtual console.Show less
1Archisteamfarm Project
1Archisteamfarm
Jun 17, 2026
Jul 26, 2021
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /Api/ASF` ASF API endpoint responsible for updating global ASF config in...Show more
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /Api/ASF` ASF API endpoint responsible for updating global ASF config incorrectly removed `IPCPassword` from the resulting config when the caller did not specify it explicitly. Due to the above, it was possible for the user to accidentally remove `IPCPassword` security measure from his IPC interface when updating global ASF config, which exists as part of global config update functionality in ASF-ui. Removal of `IPCPassword` possesses a security risk, as unauthorized users may in result access the IPC interface after such modification. The issue is patched in ASF V5.1.2.4 and future versions. We recommend to manually verify that `IPCPassword` is specified after update, and if not, set it accordingly. In default settings, ASF is configured to allow IPC access from `localhost` only and should not affect majority of users.Show less
1Motorola
1Cx2 Firmware
Jun 17, 2026
Jul 21, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid.
1Basixonline
1Nex Forms
Jun 17, 2026
Jul 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.