← Back
CWE-287

4,495 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,495)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tecrail
1Responsive Filemanager
Nov 21, 2024
Oct 10, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files.
3Debian
StarwindsoftwareTinc Vpn
3Debian Linux
Starwind Virtual SanTinc
Nov 21, 2024
Oct 10, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.
2Starwindsoftware
Tinc Vpn
2Starwind Virtual San
Tinc
Nov 21, 2024
Oct 10, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
1Descor
1Infocad Fm
Nov 21, 2024
Oct 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
1Intelbras
1Nplug Firmware
Nov 21, 2024
Oct 10, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by using "admin:" as the name of a cookie.
1Juniper
1Junos
Nov 21, 2024
Oct 10, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially...Show more
An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are Juniper Networks Junos OS: 15.1X49 versions prior to 15.1X49-D30 on vSRX.Show less
1Juniper
1Junos
Nov 21, 2024
Oct 10, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by default on Junos. There is no documented...Show more
If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by default on Junos. There is no documented CLI command to enable this service. However, an undocumented CLI command allows a privileged Junos user to enable RSH service and disable PAM, and hence expose the system to unauthenticated root access. When RSH is enabled, the device is listing to RSH connections on port 514. This issue is not exploitable on platforms where Junos release is based on FreeBSD 10+. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D75 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on QFX/EX Series; 15.1 versions prior to 15.1R4-S9, 15.1R6-S6, 15.1R7; 15.1X49 versions prior to 15.1X49-D131, 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400 Series; 15.1X53 versions prior to 15.1X53-D67 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D233 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D471, 15.1X53-D490 on NFX Series; 16.1 versions prior to 16.1R3-S9, 16.1R4-S9, 16.1R5-S4, 16.1R6-S4, 16.1R7; 16.2 versions prior to 16.2R2-S5; 17.1 versions prior to 17.1R1-S7, 17.1R2-S7, 17.1R3; 17.2 versions prior to 17.2R1-S6, 17.2R2-S4, 17.2R3; 17.2X75 versions prior to 17.2X75-D110, 17.2X75-D91; 17.3 versions prior to 17.3R1-S4, 17.3R2-S2, 17.3R3; 17.4 versions prior to 17.4R1-S3, 17.4R2; 18.2X75 versions prior to 18.2X75-D5.Show less
1Juniper
1Junos
Nov 21, 2024
Oct 10, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configur...Show more
An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configuration has the PermitEmptyPasswords option set to "yes". Affected releases are Juniper Networks Junos OS: 18.1 versions prior to 18.1R4 on NFX Series.Show less
1Telegram
1Telegram
Nov 21, 2024
Oct 9, 2018
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFa...Show more
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurredShow less
1Telegram
1Telegram
Nov 21, 2024
Oct 9, 2018
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In oth...Show more
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurredShow less
1D Link
3Dir 809 A1 Firmware
Dir 809 A2 FirmwareDir 809 Guestzone Firmware
Nov 21, 2024
Oct 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file.
1Extplorer
1Extplorer
Nov 21, 2024
Oct 7, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.
1Cisco
1Ios Xe
Nov 21, 2024
Oct 5, 2018
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. T...Show more
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication mechanisms for certain commands. An attacker could exploit this vulnerability by requesting access to the root shell of an affected device, after the shell access feature has been enabled. A successful exploit could allow the attacker to bypass authentication and gain unrestricted access to the root shell of the affected device.Show less
1Cisco
1Umbrella
Nov 21, 2024
Oct 5, 2018
N/A· v4
9.1 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The vulnerability is due to insufficient authentication c...Show more
A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The vulnerability is due to insufficient authentication configurations for the API interface of Cisco Umbrella. An attacker could exploit this vulnerability to view and potentially modify data for their organization or other organizations. A successful exploit could allow the attacker to read or modify data across multiple organizations.Show less
1Icecoldapps
1Servers Ultimate
Nov 21, 2024
Oct 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary code by uploading PHP scripts.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Oct 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
1Suse
1Subscription Management Tool
Nov 21, 2024
Oct 4, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
1Mcafee
1Data Loss Prevention Endpoint
Jun 17, 2026
Oct 3, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditio...Show more
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.Show less
1Entes
1Emg 12 Firmware
Nov 21, 2024
Oct 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a specially crafted URL. This could allow for remote code execution.
1D Link
1Dir 823g Firmware
Nov 21, 2024
Oct 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, which allows remote attackers to execute arbitrary code.