CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, inc...Show more |
3Debian MuttNeomutt3Debian Linux MuttNeomuttJun 17, 2026 Nov 23, 2020 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continu...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Nov 23, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By us...Show more |
When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions. |
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access. |
1Scratchverifier 1Scratchverifier Jun 17, 2026 Nov 20, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's account on any site that uses ScratchVerifier for logins. A possible exploitation would follow these st...Show more |
1Johnsoncontrols 2C Cure Web Victor WebJun 17, 2026 Nov 19, 2020 N/A· v4 5.3 MEDIUM· v3 5.7 MEDIUM· v2 A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use...Show more |
2Debian Influxdata2Debian Linux InfluxdbJun 17, 2026 Nov 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret). |
1Basetech 1Ge 131 Bt 1837836 Firmware Jun 17, 2026 Nov 17, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream. |
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8 |
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information. |
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information. |
ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is fo...Show more |
1Bd 2Alaris 8015 Pcu Firmware Alaris Systems ManagerJun 17, 2026 Nov 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a network session authentication vulnerability within the authen...Show more |
An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A re...Show more |
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, use...Show more |
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw tha...Show more |
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise...Show more |
In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP ser...Show more |
2Debian Saltstack2Debian Linux SaltJun 17, 2026 Nov 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH. |