← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Basixonline
1Nex Forms
Jun 17, 2026
Jul 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
1Learningdigital
1Orca Hcm
Jun 17, 2026
Jul 19, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modi...Show more
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.Show less
1Ibm
2Infosphere Change Data Capture
Infosphere Data Replication
Jun 17, 2026
Jul 16, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Forc...Show more
IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834Show less
1Idrive
1Remotepc
Jun 17, 2026
Jul 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980.
1Vmware
2Cloud Foundation
Esxi
Jun 17, 2026
Jul 13, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a s...Show more
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.Show less
1Mitsubishi
19Ae 200a Firmware
Ae 200e FirmwareAe 50a Firmware+16 more
Jun 17, 2026
Jul 13, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3.35, AG-150A-A Ver.3.20 and prior, AG-150...Show more
Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3.35, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior) and Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) allows a remote authenticated attacker to impersonate administrators to disclose configuration information of the air conditioning system and tamper information (e.g. operation information and configuration of air conditioning system) by exploiting this vulnerability.Show less
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used user...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.Show less
1Halo
1Halo
Jun 17, 2026
Jul 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.
1Fortinet
1Fortinet Single Sign On
Jun 17, 2026
Jul 12, 2021
N/A· v4
9.6 CRITICAL· v3
5.8 MEDIUM· v2
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UD...Show more
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.Show less
1Edgexfoundry
1Edgex Foundry
Jun 17, 2026
Jul 9, 2021
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the Edge...Show more
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is configured for OAuth2 authentication and a proxy user is created, the client_id and client_secret required to obtain an OAuth2 authentication token are set to the username of the proxy user. A remote network attacker can then perform a dictionary-based password attack on the OAuth2 token endpoint of the API gateway to obtain an OAuth2 authentication token and use that token to make authenticated calls to EdgeX microservices from an untrusted network. OAuth2 is the default authentication method in EdgeX Edinburgh release. The default authentication method was changed to JWT in Fuji and later releases. Users should upgrade to the EdgeX Ireland release to obtain the fix. The OAuth2 authentication method is disabled in Ireland release. If unable to upgrade and OAuth2 authentication is required, users should create OAuth2 users directly using the Kong admin API and forgo the use of the `security-proxy-setup` tool to create OAuth2 users.Show less
1Samsung
1Knox Cloud Services
Jun 17, 2026
Jul 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.
1Google
1Android
Jun 17, 2026
Jul 8, 2021
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
1A Stage Inc
2At 40cm01sr Firmware
Sct 40cm01sr Firmware
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet.
1Stellar
1Js Stellar Sdk
Jun 17, 2026
Jul 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads an...Show more
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transaction including verifying that the `serverAccountID` has signed the transaction. In js-stellar-sdk before version 8.2.3, the function does not verify that the server has signed the transaction. Applications that also used `Utils.verifyChallengeTxThreshold` or `Utils.verifyChallengeTxSigners` to verify the signatures including the server signature on the challenge transaction are unaffected as those functions verify the server signed the transaction. Applications calling `Utils.readChallengeTx` should update to version 8.2.3, the first version with a patch for this vulnerability, to ensure that the challenge transaction is completely valid and signed by the server creating the challenge transaction.Show less
1Zyxel
37Usg1000 Firmware
Usg100 FirmwareUsg1100 Firmware+34 more
Jun 17, 2026
Jul 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which co...Show more
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.Show less
1Broadcom
8Symantec Advanced Secure Gateway 500 10 Firmware
Symantec Advanced Secure Gateway S200 30 FirmwareSymantec Advanced Secure Gateway S200 40 Firmware+5 more
Jun 17, 2026
Jun 30, 2021
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the ap...Show more
The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the appliance configuration and policy, and shutdown/restart the appliance.Show less
1Opensuse
1Cryptctl
Jun 17, 2026
Jun 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This i...Show more
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.Show less
1Weidmueller
8Ie Wl Bl Ap Cl Eu Firmware
Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 more
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret s...Show more
In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.Show less
2Etinet
Hpe
2Backbox E4.09 Firmware
Backbox H4.09 Firmware
Jun 17, 2026
Jun 25, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verif...Show more
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verifying the Password returns 0 (no error). The reason is that the user is not running the XYGate application. Hence, BBSV assumes the Password is correct. For H4.09, the affected version isT0954V04^AAO. For E4.09, the affected version is 22SEP2020. Note: If your current version is E4.10-16MAY2021 (version procedure T9999V04_16MAY2022_BPAKETI_10), a hotfix (FIXPAK-19OCT-2022) is available in version E4.10-19OCT2022. Resolution to CVE-2021-33895 in version E4.11-19OCT2022Show less
1Vmware
1Carbon Black App Control
Jun 17, 2026
Jun 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be a...Show more
VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate.Show less