CWE-287
4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,492)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Infinispan Redhat2Infinispan Jboss Data GridNov 21, 2024 Jul 16, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name. |
1Hughes 4Dw7000 Firmware Hn7000s FirmwareHn7000sm Firmware+1 moreNov 21, 2024 Jul 13, 2018 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible via telnet and does...Show more |
1Jqueryform 1Php Formmail Generator Nov 21, 2024 Jul 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by navigating directly to /admin.php?mod=admin&func=panel |
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute. |
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device. |
1Microsoft 3Asp.net Core Asp.net Model View ControllerAsp.net WebpagesJun 17, 2026 Jul 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET...Show more |
4Ceph DebianOpensuse+1 more10Ceph Ceph StorageCeph Storage Mon+7 moreNov 21, 2024 Jul 10, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature chec...Show more |
3Debian OpensuseRedhat10Ceph Ceph StorageCeph Storage Mon+7 moreNov 21, 2024 Jul 10, 2018 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can us...Show more |
4Ceph DebianOpensuse+1 more9Ceph Ceph StorageCeph Storage Mon+6 moreNov 21, 2024 Jul 10, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous...Show more |
1Thetrackr 1Trackr Bravo Firmware Nov 21, 2024 Jul 6, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been release...Show more |
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised. |
1Dellemc 1Elastic Cloud Storage Nov 21, 2024 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to read and modify S3 objects by supplying specially crafted S3...Show more |
1Siemens 2Siclock Tc100 Firmware Siclock Tc400 FirmwareNov 21, 2024 Jul 3, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative access to the device's management interface could lock out legitimate users. Manual in...Show more |
1Siemens 2Siclock Tc100 Firmware Siclock Tc400 FirmwareNov 21, 2024 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could potentially circumvent the authentication mechanism if he/she is a...Show more |
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request. |
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discov...Show more |
1Hycus Cms Project 1Hycus Cms Nov 21, 2024 Jun 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials. |
Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to execute arbitrary code via Java management extensions (JMX). |
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors. |
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and...Show more |