← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arubanetworks
1Airwave Glass
Jun 17, 2026
Jan 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be...Show more
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately gain administrative access on the web administrative interface.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 15, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link
1Loxone
1Miniserver Gen 1 Firmware
Jun 17, 2026
Jan 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofin...Show more
Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofing these devices) can continue to use an unauthenticated cloud service for an indeterminate time period (possibly forever). Once an individual device's firmware is updated, and authentication occurs once, the cloud service recategorizes the device so that authentication is subsequently always required, and spoofing cannot occur.Show less
1Nec
2Univerge Sv8500 Firmware
Univerge Sv9500 Firmware
Jun 17, 2026
Jan 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the informat...Show more
Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific URL.Show less
1Nec
1Baseboard Management Controller
Jun 17, 2026
Jan 13, 2021
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Re...Show more
Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied allows remote attackers to bypass authentication and then obtain/modify BMC setting information, obtain monitoring information, or reboot/shut down the vulnerable product via unspecified vectors.Show less
1Microsoft
1Bot Framework Software Development Kit
Jun 17, 2026
Jan 12, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Bot Framework SDK Information Disclosure Vulnerability
1Ithemes
1Ithemes Security
Jun 17, 2026
Jan 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.
1Limit Login Attempts Project
1Limit Login Attempts
Nov 21, 2024
Jan 6, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
1Asus
1Dsl N17u Firmware
Jun 17, 2026
Jan 4, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_us...Show more
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiViewTools_Password= and uiViewTools_PasswordConfirm= substrings.Show less
1Hgiga
10Msr45 Isherlock Antispam
Msr45 Isherlock AuditMsr45 Isherlock Base+7 more
Jun 17, 2026
Dec 31, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
1Netgear
1Dgn2200 Firmware
Jun 17, 2026
Dec 30, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365).
1Huawei
4Cloudengine 12800 Firmware
Cloudengine 5800 FirmwareCloudengine 6800 Firmware+1 more
Jun 17, 2026
Dec 29, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to...Show more
There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to bypass current verification mechanism. This can compromise normal service.Show less
1Zammad
1Zammad
Jun 17, 2026
Dec 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be...Show more
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.Show less
1Abb
2Symphony + Historian
Symphony + Operations
Jun 17, 2026
Dec 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process.
1Dlink
1Dsl2888a Firmware
Jun 17, 2026
Dec 22, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
1Emerson
4X Stream Enhanced Xefd Firmware
X Stream Enhanced Xegk FirmwareX Stream Enhanced Xegp Firmware+1 more
Jun 17, 2026
Dec 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an att...Show more
Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.Show less
1Linux Pam
1Linux Pam
Jun 17, 2026
Dec 18, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it...Show more
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.Show less
1Trendmicro
1Interscan Web Security Virtual Appliance
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-...Show more
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.Show less
1Magic Home Pro Project
1Magic Home Pro
Jun 17, 2026
Dec 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration...Show more
The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.Show less
1Ibm
1Connect\
Jun 17, 2026
Dec 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.