CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentication vulnerability. The system has a logic judge error under certain scenario. Successful exploit co...Show more |
2Debian Json Jwt Project2Debian Linux Json JwtJun 17, 2026 Nov 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. |
1Medtronic 2Valleylab Ft10 Energy Platform Firmware Valleylab Ls10 Energy Platform FirmwareJun 17, 2026 Nov 8, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the...Show more |
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request. |
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate session validation setting for a storefront...Show more |
5Debian FedoraprojectPypa+2 more6Debian Linux FedoraOpenshift+3 moreNov 21, 2024 Nov 5, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. |
1Cisco 3Firepower Services Software For Asa Firepower Threat DefenseSecure Firewall Management CenterJun 17, 2026 Nov 5, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, re...Show more |
1Cisco 1Enterprise Chat And Email Jun 17, 2026 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication...Show more |
Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, the attacker can view...Show more |
1Sierrawireless 1Airlink Es450 Firmware Nov 21, 2024 Oct 31, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configur...Show more |
5Capturecctv HachiHuntcctv+2 more20Cdr 0410ve Firmware Cdr 0820vde FirmwareDr6 704a4h Firmware+17 moreNov 21, 2024 Oct 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration. |
1Milesight 1Ip Security Camera Firmware Nov 21, 2024 Oct 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource. |
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via...Show more |
An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdminxxxxxxxxx (e.g., FSAdmin123456789) on the server that hosts the LAN C...Show more |
1Cobham 1Explorer 710 Firmware Jun 17, 2026 Oct 10, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execut...Show more |
1Netgear 33Ac1450 Firmware D8500 FirmwareDc112a Firmware+30 moreJun 17, 2026 Oct 9, 2019 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a va...Show more |
2Canonical Opendev2Octavia Ubuntu LinuxJun 17, 2026 Oct 8, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue...Show more |
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens. |
The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arb...Show more |
When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough t...Show more |