← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
12Asa 5500 Firmware
Asa 5510 FirmwareAsa 5512 X Firmware+9 more
Nov 21, 2024
Feb 19, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providin...Show more
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker must have the correct primary credentials in order to successfully exploit this vulnerability.Show less
1Freebsd
1Freebsd
Nov 21, 2024
Feb 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context...Show more
OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login (1) without a password or (2) with an incorrect password.Show less
1Getbutterfly
1Portable Phpmyadmin
Nov 21, 2024
Feb 18, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities
1Huawei
5Hege 560 Firmware
Osca 550 FirmwareOsca 550a Firmware+2 more
Jun 17, 2026
Feb 18, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker can access the device...Show more
Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker can access the device physically and perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker obtain high privilege.Show less
1Huawei
1P30 Firmware
Jun 17, 2026
Feb 18, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation of certain application, an attacker should trick the user into install...Show more
HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation of certain application, an attacker should trick the user into installing a malicious application to exploit this vulnerability. Successful exploit could allow the attacker to bypass the authentication to perform unauthorized operations.Show less
1Huawei
4Osca 550 Firmware
Osca 550a FirmwareOsca 550ax Firmware+1 more
Jun 17, 2026
Feb 18, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentication vulnerability. The software does not require a strong credential when the user trying to do ce...Show more
Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentication vulnerability. The software does not require a strong credential when the user trying to do certain operations. Successful exploit could allow an attacker to pass the authentication and do certain operations by a weak credential.Show less
1Kaseya
1Virtual System Administrator
Nov 21, 2024
Feb 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentica...Show more
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.Show less
1S3india
1Husky Rtu 6049 E70 Firmware
Jun 17, 2026
Feb 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to re...Show more
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is a different issue than CVE-2019-16879 and CVE-2019-20045.Show less
1Extrun
1Ilbo
Jun 17, 2026
Feb 14, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by th...Show more
ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.Show less
1Trendnet
1Ts S402 Firmware
Nov 21, 2024
Feb 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TRENDnet TS-S402 has a backdoor to enable TELNET.
1Simplisafe
1Simplisafe Ss3 Firmware
Jun 17, 2026
Feb 13, 2020
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connects to.
2Intel
Netapp
2Converged Security Management Engine Firmware
Steelstore Cloud Integrated Storage
Jun 17, 2026
Feb 13, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable esca...Show more
Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.Show less
1Bssys
1Rbs Bs Client. Retail Client
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged fu...Show more
A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged function.Show less
1Openvpn
1Openvpn Access Server
Jun 17, 2026
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).
1Shaman Project
1Shaman
Nov 21, 2024
Feb 12, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never en...Show more
Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.Show less
2Istio
Redhat
2Istio
Openshift Service Mesh
Jun 17, 2026
Feb 12, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even i...Show more
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.Show less
1Microsoft
1Exchange Server
Jun 17, 2026
Feb 11, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
1Kde
1Paste Applet
Nov 21, 2024
Feb 11, 2020
N/A· v4
8.4 HIGH· v3
2.1 LOW· v2
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a...Show more
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.Show less
1Ammyy
1Ammyy Admin
Nov 21, 2024
Feb 11, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from th...Show more
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.Show less
1Atutor
1Atutor
Nov 21, 2024
Feb 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.