← Back
CWE-287

4,499 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,499)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianMozilla+1 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+7 more
Nov 25, 2025
Feb 5, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is ins...Show more
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.Show less
1Lcds
1Laquis Scada
Nov 21, 2024
Feb 5, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.
1Abb
1Cms 770 Firmware
Nov 21, 2024
Jan 31, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user authentication mechanism.
1Abb
2Eth Fw Firmware
Fw Firmware
Nov 21, 2024
Jan 31, 2019
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicious language file by bypassing the user authentication mechanism.
1Comodo
1Unified Threat Management Firewall
Nov 21, 2024
Jan 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
1Ibm
1Datapower Gateway
Nov 21, 2024
Jan 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensiti...Show more
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.Show less
1Hetronic
5Bms Hl Firmware
Dc Mobile FirmwareEs Can Hl Firmware+2 more
Nov 21, 2024
Jan 25, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled...Show more
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.Show less
1Mcafee
1Mvision Endpoint
Jun 17, 2026
Jan 23, 2019
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated administrator users --> administrators to Remove MVision Endpoint via...Show more
Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated administrator users --> administrators to Remove MVision Endpoint via unspecified vectors.Show less
1Bmc
1Patrol Agent
Nov 21, 2024
Jan 17, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was fo...Show more
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was found that by default the PatrolCli / PATROL Agent application only verifies if the password provided for the given username is correct; it does not verify the permissions of the user on the network. This means if you have PATROL Agent installed on a high value target (domain controller), you can use a low privileged domain user to authenticate with PatrolCli and then connect to the domain controller and run commands as SYSTEM. This means any user on a domain can escalate to domain admin through PATROL Agent. NOTE: the vendor disputes this because they believe it is adequate to prevent this escalation by means of a custom, non-default configurationShow less
1Tibco
2Spotfire Analytics Platform For Aws
Spotfire Server
Nov 21, 2024
Jan 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the authentication that th...Show more
The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the authentication that theoretically may allow an attacker to gain full access to a target account, independent of configured authentication mechanisms. Affected releases are TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.0.0, and TIBCO Spotfire Server: versions up to and including 7.10.1; 7.11.0; 7.11.1; 7.12.0; 7.13.0; 7.14.0.Show less
3Etcd
FedoraprojectRedhat
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
Nov 21, 2024
Jan 14, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS cer...Show more
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.Show less
1Apple
1Mac Os X
Nov 21, 2024
Jan 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validatio...Show more
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validation.Show less
1Imperva
1Securesphere
Jun 17, 2026
Jan 10, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially cra...Show more
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.Show less
1Panasonic
1Bn Sdwbp3 Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management screen and execute an arbitrary command via unspecified vectors.
1Mnc
1Inplc Rt
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. This is a different vulnerability than CVE-2018-0669.
1Mnc
1Inplc Rt
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. This is a different vulnerability than CVE-2018-0670.
1Dlink
4Dir 822 Us Firmware
Dir 822 FirmwareDir 850l Firmware+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-880L A* before v1.20B02Beta devices allow authentication bypass.
1Microsoft
1Skype
Jun 17, 2026
Jan 8, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1703+12 more
Jun 17, 2026
Jan 8, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Window...Show more
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.Show less
1Stripe
1Stripe Api
Nov 21, 2024
Jan 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing the response under the object card{}, and reading the cvc_check informa...Show more
The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing the response under the object card{}, and reading the cvc_check information if the creation is successful without charging the actual card used in the transaction.Show less