← Back
CWE-287

4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Ikiwiki
2Debian Linux
Ikiwiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.
1Horde
1Horde Ldap
Nov 21, 2024
Apr 10, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.
1Phoenixcontact
1Ilc Plcs Firmware
Nov 21, 2024
Apr 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
1Phoenixcontact
1Ilc Plcs Firmware
Nov 21, 2024
Apr 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.
1Moodle
1Moodle
Nov 21, 2024
Apr 4, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.
1Auth0
1Auth0.js
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
1Fiberhome
1Vdsl2 Modem Hg 150 Ub Firmware
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
1Fiberhome
1Vdsl2 Modem Hg 150 Ub Firmware
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
1Elastic
1X Pack
Nov 21, 2024
Mar 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if th...Show more
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.Show less
1Westerndigital
1My Cloud Firmware
Jun 17, 2026
Mar 30, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in...Show more
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.Show less
1Qualcomm
14Apq8096au Firmware
Mdm9206 FirmwareMdm9650 Firmware+11 more
Nov 21, 2024
Mar 30, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 625, SD 650/52, SD 820, SD 835, it is pos...Show more
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 625, SD 650/52, SD 820, SD 835, it is possible for the XBL loader to skip the authentication of device config.Show less
1Siemens
1Tim 1531 Irc Firmware
Nov 21, 2024
Mar 29, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authenti...Show more
A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow to cause a denial-of-service, or read and manipulate data as well as configuration settings of the affected device. At the stage of publishing this security advisory no public exploitation is known. Siemens provides mitigations to resolve it.Show less
1Cisco
1Ios Xe
Nov 21, 2024
Mar 28, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the API to perform privileged actions on an affected device. The vulnerabilit...Show more
A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the API to perform privileged actions on an affected device. The vulnerability is due to insufficient authorization checks for requests that are sent to the REST API of the affected software. An attacker could exploit this vulnerability by sending a malicious request to an affected device via the REST API. A successful exploit could allow the attacker to selectively bypass authorization checks for the REST API of the affected software and use the API to perform privileged actions on an affected device. Cisco Bug IDs: CSCuz56428.Show less
1Cisco
1Ios
Nov 21, 2024
Mar 28, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vuln...Show more
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.Show less
1Philips
1Alice 6 Firmware
Jun 17, 2026
Mar 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct. This weakness can lead to the exposure of...Show more
In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct. This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or the ability to execute arbitrary code.Show less
1Nordvpn
1Nordvpn
Jun 17, 2026
Mar 27, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemented XPC service. This XPC service is responsible for receiving and proces...Show more
NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemented XPC service. This XPC service is responsible for receiving and processing new OpenVPN connection requests from the main application. Unfortunately this XPC service is not protected, which allows arbitrary applications to connect and send it XPC messages. An attacker can send a crafted XPC message to the privileged helper tool requesting it make a new OpenVPN connection. Because he or she controls the contents of the XPC message, the attacker can specify the location of the openvpn executable, which could point to something malicious they control located on disk. Without validation of the openvpn executable, this will give the attacker code execution in the context of the privileged helper tool.Show less
1Dell
1Emc Scaleio
Nov 21, 2024
Mar 27, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This component is deployed on every server in the ScaleIO cluster and is us...Show more
Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This component is deployed on every server in the ScaleIO cluster and is used for central management of ScaleIO nodes. A remote malicious user, having network access to LIA, could potentially exploit this vulnerability to launch brute force guessing of user names and passwords of user accounts on the LIA.Show less
1Ibm
1Tealeaf Customer Experience
Nov 21, 2024
Mar 27, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified vectors. IBM X-Force ID: 105896.
1Dlink
1Dir 850l Firmware
Jun 17, 2026
Mar 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort...Show more
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly visiting /category_view.php or /folder_view.php.Show less
1Symantec
1Norton App Lock
Nov 21, 2024
Mar 26, 2018
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, th...Show more
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, thereby allowing the individual to gain device access.Show less