CWE-287
4,500 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,500)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Coship 4Rt3050 Firmware Rt3052 FirmwareRt7620 Firmware+1 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation...Show more |
1Kentix 1Multisensor Lan Firmware Nov 21, 2024 Mar 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel. |
1Dropbear Ssh Project 1Dropbear Ssh Nov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the max...Show more |
1Cobham 2Satcom Sailor 250 Firmware Satcom Sailor 500 FirmwareNov 21, 2024 Mar 15, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), withou...Show more |
An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher. |
An issue was discovered in CapMon Access Manager 5.4.1.1005. The client applications of AccessManagerCoreService.exe communicate with this server through named pipes. A user can initiate communication with the server by...Show more |
1Intel 2Converged Security Management Engine Firmware Server Platform Services FirmwareNov 21, 2024 Mar 14, 2019 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentiall...Show more |
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user. |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Feb 28, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler...Show more |
1Broadcom 1Privileged Access Manager Jun 17, 2026 Feb 26, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration. |
An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password. |
1Cisco 1Hyperflex Hx Data Platform Jun 17, 2026 Feb 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication cont...Show more |
1Cisco 1Hyperflex Hx Data Platform Jun 17, 2026 Feb 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication co...Show more |
1Cisco 1Prime Collaboration Assurance Jun 17, 2026 Feb 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerabili...Show more |
1Yokogawa 4B/m 9000 Vp Centum VpPrm+1 moreJun 17, 2026 Feb 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) al...Show more |
1Microfocus 1Solutions Business Manager Nov 21, 2024 Feb 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. |
1Kunbus 1Pr100088 Modbus Gateway Firmware Jun 17, 2026 Feb 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the devic...Show more |
3Canonical GnomeRedhat3Enterprise Linux Gnome Display ManagerUbuntu LinuxJun 17, 2026 Feb 6, 2019 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which...Show more |
3Canonical GnomeOpensuse3Gnome Shell LeapUbuntu LinuxJun 17, 2026 Feb 6, 2019 N/A· v4 4.3 MEDIUM· v3 4.6 MEDIUM· v2 It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts,...Show more |
WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and manipulate sensitive information. |