← Back
CWE-287

4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
201288h V5 Firmware
2288h V5 Firmware2488 V5 Firmware+17 more
Jun 17, 2026
Jun 1, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to i...Show more
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables low privileged users to get or modify passwords of highly privileged users.Show less
1Console Io Project
1Console Io
Nov 21, 2024
May 31, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2...Show more
console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2.2.13 and earlier is able to run. This means that if console-io was running from root, the attacker would have full access to the system. This vulnerability exists because the console-io application does not configure socket.io to require authentication, which allows a malicious user to connect via a websocket to send commands and receive the response.Show less
1Multidots
1Woocommerce Category Banner Management
Nov 21, 2024
May 31, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone ca...Show more
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.Show less
1Vgate
1Icar 2 Wi Fi Obd2 Firmware
Nov 21, 2024
May 30, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands...Show more
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands to the car (different for every vendor / car product line / car). No authentication is needed, which allows attacks from the local Wi-Fi network.Show less
1Dwyl
1Hapi Auth Jwt2
Nov 21, 2024
May 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
1Paypal Ipn Project
1Paypal Ipn
Nov 21, 2024
May 29, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a requ...Show more
paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a request using the simulator that would fool any application which does not explicitly check for test_ipn in production.Show less
1Atisystem
4Alert4000 Firmware
Hpss16 FirmwareHpss32 Firmware+1 more
Jun 17, 2026
May 25, 2018
N/A· v4
3.1 LOW· v3
2.9 LOW· v2
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability caused by specially crafted malicious radio transmissions may allow an attacker...Show more
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability caused by specially crafted malicious radio transmissions may allow an attacker to remotely trigger false alarms.Show less
1Accellion
1Kiteworks
Nov 21, 2024
May 24, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
1Dlink
1Dsl 3782 Firmware
Jun 17, 2026
May 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform a...Show more
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.Show less
1Cisco
1Digital Network Architecture Center
Nov 21, 2024
May 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and access critical services. The vulnerability is due to...Show more
A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and access critical services. The vulnerability is due to a failure to normalize URLs prior to servicing requests. An attacker could exploit this vulnerability by submitting a crafted URL designed to exploit the issue. A successful exploit could allow the attacker to gain unauthenticated access to critical services, resulting in elevated privileges in DNA Center. This vulnerability affects Cisco DNA Center Software Releases prior to 1.1.2. Cisco Bug IDs: CSCvi09394.Show less
1Jenkins
1Jenkins
Nov 21, 2024
May 15, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).
1Mimobaby
1Mimo Baby 2 Firmware
Nov 21, 2024
May 15, 2018
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperatur...Show more
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a replay or spoofing attack.Show less
1Ehcp
1Easy Hosting Control Panel
Jun 17, 2026
May 11, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password.
1Huawei
201288h V5 Firmware
2288h V5 Firmware2488 V5 Firmware+17 more
Jun 17, 2026
May 10, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validat...Show more
Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation.Show less
1Huawei
2Mate 9 Firmware
Mate 9 Pro Firmware
Jun 17, 2026
May 10, 2018
N/A· v4
6.2 MEDIUM· v3
7.2 HIGH· v2
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains th...Show more
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some specific operations.Show less
1Silextechnology
4Geh 500 Firmware
Geh Sd 320an FirmwareSd 320an Firmware+1 more
Jun 17, 2026
May 9, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings.
1Redhat
1Wildfly
Nov 21, 2024
May 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms...Show more
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference" implies "effectively unsecured." The vendor explicitly supports these unsecured configurations because they have valid use cases during developmentShow less
1Wildfly
1Wildfly
Nov 21, 2024
May 9, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once...Show more
An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration present by default (auto-deployment) permits an anonymous user to deploy a malicious .war file, leading to remote code execution. NOTE: the vendor indicates that anonymous access is not available in the default installation; however, it remains optional because there are several use cases for it, including development environments and network architectures that have a proxy server for access control to the WildFly serverShow less
1Lenovo
11Flex System X240 M5 Bios
Flex System X280 X6 BiosFlex System X480 X6 Bios+8 more
Nov 21, 2024
May 4, 2018
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the...Show more
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.Show less
1Dlink
1Dir 601 Firmware
Nov 21, 2024
May 4, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.