CWE-287
4,495 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,495)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958. |
1Lenovo 20Ez Media & Backup Center Firmware Ix2 FirmwareIx4 300d Firmware+17 moreJun 17, 2026 Sep 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cook...Show more |
1Hpe 1Storageworks Xp7 Automation Director Jun 17, 2026 Sep 27, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage syst...Show more |
1Ibm 1Rational Engineering Lifecycle Manager Nov 21, 2024 Sep 25, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-For...Show more |
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ U...Show more |
2Intel Lenovo32Core I3 Core I5Core I7+29 moreNov 21, 2024 Sep 21, 2018 N/A· v4 7.6 HIGH· v3 4.6 MEDIUM· v2 Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor...Show more |
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instan...Show more |
1Symantec 1Messaging Gateway Nov 21, 2024 Sep 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in...Show more |
1Mcafee 1Application And Change Control Nov 21, 2024 Sep 18, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility. |
1Circontrol 1Circarlife Scada Nov 21, 2024 Sep 18, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html. |
1Circontrol 1Circarlife Scada Nov 21, 2024 Sep 18, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository. |
1Western Digital 12My Cloud Dl2100 My Cloud Dl4100 FirmwareMy Cloud Ex2100 Firmware+9 moreNov 21, 2024 Sep 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin use...Show more |
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo s...Show more |
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A HTTP request can allow for a user to perform a firmware upgrade using a crafte...Show more |
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits. |
1Pulsesecure 1Pulse Secure Desktop Jun 17, 2026 Sep 12, 2018 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privilege...Show more |
IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication mechanisms once the initial login is completed. IBM X-Force ID: 148691. |
2Debian Openafs2Debian Linux OpenafsNov 21, 2024 Sep 12, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RP...Show more |
1Kone 1Group Controller Firmware Nov 21, 2024 Sep 7, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or authorization, aka KONE-03. |
1Furuno 2Felcom 250 Firmware Felcom 500 FirmwareNov 21, 2024 Sep 6, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication. |