CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system. |
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3. |
1Moxa 2Oncell G3150 Hspa T Firmware Oncell G3150 Hspa FirmwareNov 21, 2024 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute force parameters required to bypass authentication and access the web in...Show more |
1Dlink 2Dcs 1100 Firmware Dcs 1130 FirmwareNov 21, 2024 Jul 2, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on D-Link DCS-1130 and DCS-1100 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary loads at address 0x00012CF...Show more |
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without...Show more |
1Medtronic 19Minimed 508 Firmware Minimed Paradigm 511 FirmwareMinimed Paradigm 512 Firmware+16 moreJun 17, 2026 Jun 28, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication pr...Show more |
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a craft...Show more |
1Actiontec 1Web6000q Firmware Nov 21, 2024 Jun 27, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers. |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an...Show more |
2Debian Vmware2Debian Linux Spring SecurityJun 17, 2026 Jun 26, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging Plain...Show more |
1Polycom 2Better Together Over Ethernet Connector Unified Communications SoftwareJun 17, 2026 Jun 24, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and th...Show more |
In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause. Remote user interaction is needed for exploitation.Product: AndroidVersio...Show more |
EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD elem...Show more |
1Columbiaweather 1Weather Microserver Firmware Nov 21, 2024 Jun 18, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device. |
1Phoenixcontact 2Axc F 2152 Firmware Axc F 2152 Starterkit FirmwareJun 17, 2026 Jun 18, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD...Show more |
1Getvera 2Veraedge Firmware Veralite FirmwareNov 21, 2024 Jun 17, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage the device. As a part of the functionality the device allows a user to i...Show more |
1Getvera 2Veraedge Firmware Veralite FirmwareNov 21, 2024 Jun 17, 2019 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and can also be accessed via port 80 using the url "/port_3480". It seems th...Show more |
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.187766/dynamic/js/setup.js.localized file on the router's webserver, al...Show more |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Jun 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a mal...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jun 12, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, cou...Show more |