← Back
CWE-287

4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,502)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
3Integrated Management Controller Supervisor
Ucs DirectorUcs Director Express For Big Data
Jun 17, 2026
Aug 21, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote att...Show more
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to gain full administrative access to the affected device.Show less
1Cisco
2Ucs Director
Ucs Director Express For Big Data
Jun 17, 2026
Aug 21, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actio...Show more
A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper authentication request handling. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an unprivileged attacker to access and execute arbitrary actions through certain APIs.Show less
1Cisco
3Integrated Management Controller Supervisor
Ucs DirectorUcs Director Express For Big Data
Jun 17, 2026
Aug 21, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote att...Show more
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user authentication. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to use the acquired session token to gain full administrator access to the affected device.Show less
1Forcepoint
1Next Generation Firewall
Jun 17, 2026
Aug 20, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially allows unauthorized users to bypass passwor...Show more
Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services protected by the NGFW Engine. The vulnerability affects the following NGFW features when the LDAP authentication method is used as the backend authentication: IPsec VPN, SSL VPN or Browser-based user authentication. The vulnerability does not apply when any other backend authentication is used. The RADIUS authentication method is not vulnerable, for example.Show less
2Debian
Gonicus
2Debian Linux
Gosa
Jun 17, 2026
Aug 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is p...Show more
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.Show less
1Arista
1Eos
Nov 21, 2024
Aug 15, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Aug 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
1Huawei
1Pcmanager
Jun 17, 2026
Aug 13, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mode data properly, successful exploit could result in malicious code exe...Show more
PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mode data properly, successful exploit could result in malicious code execution.Show less
1Eq 3
2Homematic Ccu2 Firmware
Homematic Ccu3 Firmware
Jun 17, 2026
Aug 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.
1Mailpile
1Mailpile
Nov 21, 2024
Aug 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys.
1Cisco
1Enterprise Network Function Virtualization Infrastructure
Jun 17, 2026
Aug 8, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-bas...Show more
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerability is due to an incorrect implementation of authentication in the web-based management interface. An attacker could exploit this vulnerability by sending a crafted authentication request to the web-based management interface on an affected system. A successful exploit could allow the attacker to view limited configuration details and potentially upload a virtual machine image.Show less
1Loom
1Loom
Jun 17, 2026
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods i...Show more
Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods in which a user is recording a video with the application. The same attack vector can be used to crash the application at any time.Show less
1Microdigital
3Mdc N2190v Firmware
Mdc N4090 FirmwareMdc N4090w Firmware
Jun 17, 2026
Aug 6, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 because any valid cookie can be used to make requests as an admin.
1Nvidia
1Shield Experience
Jun 17, 2026
Aug 6, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authenticated, which may lead to code execution, denial of service, escalati...Show more
NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authenticated, which may lead to code execution, denial of service, escalation of privileges, and information disclosure, code execution, denial of service, or escalation of privilegesShow less
1Tcl
1Alcatel Linkzone Firmware
Jun 17, 2026
Aug 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrat...Show more
The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password.Show less
1Ibm
1Data Protection
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.8 HIGH· v3
1.9 LOW· v2
IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed in plain text in the ERP trace file. IBM X-Force ID: 154280.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).