← Back
CWE-287

4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Apache
CanonicalDebian+2 more
13Cloud Backup
Clustered Data OntapDebian Linux+10 more
Nov 21, 2024
Mar 26, 2018
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a co...Show more
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.Show less
1Geutebrueck
2G Cam/efd 2250 Firmware
Topfd 2125 Firmware
Jun 17, 2026
Mar 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.
1Meco
1Usb Memory Stick With Fingerprint Firwmare
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical access can send a static p...Show more
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical access can send a static packet to a serial port exposed on the PCB to unlock the key and get access to the data without possessing the required fingerprint.Show less
1Ucopia
1Wireless Appliance Firmware
Nov 21, 2024
Mar 22, 2018
N/A· v4
6.7 MEDIUM· v3
6.5 MEDIUM· v2
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote attackers to escape the...Show more
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote attackers to escape the shell and escalate their privileges by uploading a .bashrc file containing the /bin/sh string. In some situations, authentication can be achieved via the bhu85tgb default password for the admin account.Show less
1Ge
1Centricity Pacs Ra1000
Nov 21, 2024
Mar 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to by...Show more
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.Show less
1Ge
1Xeleris
Nov 21, 2024
Mar 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote a...Show more
GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.Show less
1Ge
1Gemnet License Server
Nov 21, 2024
Mar 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authenticat...Show more
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.Show less
1Ge
1Infinia Hawkeye 4 Firmware
Nov 21, 2024
Mar 20, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker t...Show more
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.Show less
1Pivotal Software
1Gemfire For Pivotal Cloud Foundry
Nov 21, 2024
Mar 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
1Embedthis
1Appweb
Jun 17, 2026
Mar 15, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form an...Show more
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.Show less
1Woocommerce Filter
1Woocommerce Products Filter
Jun 17, 2026
Mar 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemente...Show more
A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without any authentication. WordPress shortcode markup in the "shortcode" parameters would be evaluated. Normally unauthenticated users can't evaluate shortcodes as they are often sensitive.Show less
1Kaseya
1Unitrends Backup
Jun 17, 2026
Mar 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts param...Show more
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.Show less
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Nov 21, 2024
Mar 14, 2018
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709...Show more
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how CredSSP validates request during the authentication process, aka "CredSSP Remote Code Execution Vulnerability".Show less
1Datalust
1Seq
Jun 17, 2026
Mar 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","Value":false' in an api/settings/setting-isauthenticationenabled PUT re...Show more
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","Value":false' in an api/settings/setting-isauthenticationenabled PUT request.Show less
3Debian
ParamikoRedhat
11Ansible Engine
CloudformsDebian Linux+8 more
Jun 17, 2026
Mar 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly chec...Show more
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.Show less
1Hanwha Security
2Snh V6410pn Firmware
Snh V6410pnw Firmware
Jun 17, 2026
Mar 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authentication bypass in Hanwha Techwin Smartcams
1Hanwha Security
2Snh V6410pn Firmware
Snh V6410pnw Firmware
Jun 17, 2026
Mar 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unsecured way of firmware update in Hanwha Techwin Smartcams
1Asyncssh Project
1Asyncssh
Jun 17, 2026
Mar 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.
1Haxx
1Curl
Nov 21, 2024
Mar 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by U...Show more
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.Show less
1Abine
1Blur
Jun 17, 2026
Mar 11, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authentication and macOS disk-encryption protection mechanisms, and consequently exfiltrate secured data,...Show more
The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authentication and macOS disk-encryption protection mechanisms, and consequently exfiltrate secured data, because the right-click context menu is not secured.Show less