CWE-287
4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,492)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dasannetworks 1Gpon Router Firmware Nov 5, 2025 May 4, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ o...Show more |
1Cisco 2Aironet Access Point Software Wireless Lan Controller SoftwareNov 21, 2024 May 2, 2018 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authent...Show more |
Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface. |
Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and use it as an update. |
1Watchguard 3Ap100 Firmware Ap102 FirmwareAp200 FirmwareNov 21, 2024 Apr 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (...Show more |
1Ibm 1Qradar Security Information And Event Manager Nov 21, 2024 Apr 26, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824. |
1Abbott 7Accent Firmware Accent Mri FirmwareAccent St Firmware+4 moreNov 21, 2024 Apr 25, 2018 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to...Show more |
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulner...Show more |
1Phpliteadmin 1Phpliteadmin Nov 21, 2024 Apr 25, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for the user-provided login password, it is possible to login with a simpler...Show more |
4Canonical DebianPackagekit Project+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Apr 23, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable pa...Show more |
1Ibm 2Sterling B2b Integrator Sterling File GatewayNov 21, 2024 Apr 20, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp pa...Show more |
VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitima...Show more |
1Cisco 1Unified Computing System Director Nov 21, 2024 Apr 19, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machin...Show more |
1Schneider Electric 57140cpu31110 Firmware 140cpu31110c Firmware140cpu43412u Firmware+54 moreJun 17, 2026 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization. |
1Qualcomm 2Sd 820 Firmware Sd 820a FirmwareNov 21, 2024 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 820 and SD 820A, the input to RPMB write response function is a buffer from HLOS that needs to be au...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss FuseUndertow+1 moreNov 21, 2024 Apr 18, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP r...Show more |
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. An attacker who is in the same subnetwork of the camera or has remote administra...Show more |
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains an HTTP message parsing function that takes a user-defined path and writ...Show more |
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_in...Show more |
2Debian Ikiwiki2Debian Linux IkiwikiNov 21, 2024 Apr 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters. |