CWE-287
4,494 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,494)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Medtronicdiabetes 9508 Minimed Insulin Pump Firmware 522 Paradigm Real Time Firmware523 Paradigm Revel Firmware+6 moreMay 22, 2025 Aug 13, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wi...Show more |
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secr...Show more |
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication. |
1Netcommwireless 1Nwl 25 Firmware Nov 21, 2024 Aug 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and profiles without authenticating the user. |
1Crestron 2Mc3 Firmware Tsw X60 FirmwareNov 21, 2024 Aug 10, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enab...Show more |
1Hp 1Centralview Fraud Risk Management Jun 17, 2026 Aug 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version. |
1Hp 1Aruba Clearpass Policy Manager Jun 17, 2026 Aug 6, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability...Show more |
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to...Show more |
1Martem 2Telem Gw6 Firmware Telem Gwm FirmwareNov 21, 2024 Jul 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process. |
Huawei mobile phones with versions earlier before Emily-AL00A 8.1.0.153(C00) have an authentication bypass vulnerability. An attacker could trick the user to connect to a malicious device. In the debug mode, the maliciou...Show more |
IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483. |
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authentic...Show more |
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jul 27, 2018 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the t...Show more |
Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically proximate attackers to bypass local security protection via specific set of circumstances. |
2Mit Redhat5Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw...Show more |
In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-i...Show more |
ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution. |
1Echelon 4I.lon 100 Firmware I.lon 600 FirmwareSmartserver 1 Firmware+1 moreJun 17, 2026 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security c...Show more |
Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature...Show more |