← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fedoraproject
1Selinux Policy
Jun 17, 2026
Aug 24, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allo...Show more
An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default when configured by the authselect tool), and that file cannot be read, the second factor is disabled. An attacker with only the knowledge of the password can then log in, bypassing 2FA.Show less
1Dbhcms Project
1Dbhcms
Jun 17, 2026
Aug 24, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table.
1Ncr
1Aptra Xfs
Jun 17, 2026
Aug 21, 2020
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to inter...Show more
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.Show less
1Philips
1Suresigns Vs4 Firmware
Jun 17, 2026
Aug 21, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficiently proves the claim is correct.
1Nodebb
1Nodebb
Jun 17, 2026
Aug 20, 2020
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io cal...Show more
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation event due via an account takeover. As a workaround you may cherry-pick the following commit from the project's repository to your running instance of NodeBB: 16cee1b03ba3eee177834a1fdac4aa8a12b39d2a. This is fixed in version 1.14.3.Show less
1Cisco
1Catalyst Center
Jun 17, 2026
Aug 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by...Show more
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker access to sensitive device information, which includes configuration files.Show less
1Huawei
1Fusioncompute
Jun 17, 2026
Aug 17, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to delete some files and cause some services abnormal.
1Ibm
1Event Streams
Jun 17, 2026
Aug 14, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 186233.
1Intel
1Led Manager For Nuc
Jun 17, 2026
Aug 13, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Improper authentication in subsystem for Intel (R) LED Manager for NUC before version 1.2.3 may allow privileged user to potentially enable denial of service via local access.
1Intel
18Compute Module Hns2600bp Firmware
Compute Module Hns2600kp FirmwareCompute Module Hns2600tp Firmware+15 more
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
18Compute Module Hns2600bp Firmware
Compute Module Hns2600kp FirmwareCompute Module Hns2600tp Firmware+15 more
Jun 17, 2026
Aug 13, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
1Intel
18Compute Module Hns2600bp Firmware
Compute Module Hns2600kp FirmwareCompute Module Hns2600tp Firmware+15 more
Jun 17, 2026
Aug 13, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Improper authentication in socket services for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjac...Show more
Improper authentication in socket services for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.Show less
1Intel
18Compute Module Hns2600bp Firmware
Compute Module Hns2600kp FirmwareCompute Module Hns2600tp Firmware+15 more
Jun 17, 2026
Aug 13, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 12, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
1Gitlab
1Gitlab
Jun 17, 2026
Aug 10, 2020
N/A· v4
9.6 CRITICAL· v3
5.5 MEDIUM· v2
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
1Digitus
1Da 70254 Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
1Lindy International
142633 Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
1Tp Link
1Tl Ps310u Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
1Robotemi
1Robox Os
Jun 17, 2026
Aug 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it automatically answer the...Show more
Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it automatically answer the attacker's calls, granting audio, video, and motor control via unspecified vectors.Show less
2Fedoraproject
Redhat
2Etcd
Fedora
Jun 17, 2026
Aug 6, 2020
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified i...Show more
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. No authentication is performed against endpoints provided in the --endpoints flag. This has been fixed in versions 3.4.10 and 3.3.23 with improved documentation and deprecation of the functionality.Show less