← Back
CWE-287

4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bmc
1Remedy Action Request System
Nov 21, 2024
Mar 10, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.
1Schneider Electric
20Ibp1110 1er Firmware
Ibp219 1er FirmwareIbp319 1er Firmware+17 more
Jun 17, 2026
Mar 9, 2018
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH ser...Show more
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.Show less
1Schneider Electric
20Ibp1110 1er Firmware
Ibp219 1er FirmwareIbp319 1er Firmware+17 more
Jun 17, 2026
Mar 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator p...Show more
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges.Show less
1Schneider Electric
20Ibp1110 1er Firmware
Ibp219 1er FirmwareIbp319 1er Firmware+17 more
Jun 17, 2026
Mar 9, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive in...Show more
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.Show less
1Ibm
2Security Access Manager
Tivoli Federated Identity Manager
Nov 21, 2024
Mar 8, 2018
N/A· v4
5.9 MEDIUM· v3
4.6 MEDIUM· v2
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker...Show more
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim users password. IBM X-Force ID: 139754.Show less
1Qnap
1Media Streaming Add On
Nov 21, 2024
Mar 8, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of...Show more
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.Show less
1Cisco
1Asyncos
Nov 21, 2024
Mar 8, 2018
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to ha...Show more
A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerability is due to incorrect FTP user credential validation. An attacker could exploit this vulnerability by using FTP to connect to the management IP address of the targeted device. A successful exploit could allow the attacker to log in to the FTP server of the Cisco WSA without having a valid password. This vulnerability affects Cisco AsyncOS for WSA Software on both virtual and hardware appliances that are running any release of Cisco AsyncOS 10.5.1 for WSA Software. The device is vulnerable only if FTP is enabled on the management interface. FTP is disabled by default. Cisco Bug IDs: CSCvf74281.Show less
1Cobub
1Razor
Jun 17, 2026
Mar 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/installation/createuserinfo requests, resulting in account creation.
1Netiq
1Privileged Account Manager
Nov 21, 2024
Mar 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PAM exposure enabling unauthenticated access to remote host
1Netapp
1Snapcenter Server
Nov 21, 2024
Mar 6, 2018
N/A· v4
7.2 HIGH· v3
6.4 MEDIUM· v2
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File Services. All users are urged to move to version 3.0.1 and perform the m...Show more
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File Services. All users are urged to move to version 3.0.1 and perform the mitigation steps or upgrade to 4.0 following the product documentation.Show less
1Moxa
4Oncell G3110 Hspa T Firmware
Oncell G3110 Hspa FirmwareOncell G3150 Hspa T Firmware+1 more
Jun 17, 2026
Mar 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only dig...Show more
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.Show less
2Microfocus
Netiq
2Edirectory
Edirectory
Nov 21, 2024
Mar 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
1Netiq
1Imanager
Nov 21, 2024
Mar 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
1Citrix
3Netscaler Application Delivery Controller
Netscaler GatewayNetscaler Sd Wan
Nov 21, 2024
Mar 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetS...Show more
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.Show less
1Apache
1Openmeetings
Nov 21, 2024
Feb 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.
1Cisco
2Elastic Services Controller
Virtual Managed Services
Nov 21, 2024
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbit...Show more
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper security restrictions that are imposed by the web-based service portal of the affected software. An attacker could exploit this vulnerability by submitting an empty password value to an affected portal when prompted to enter an administrative password for the portal. A successful exploit could allow the attacker to bypass authentication and gain administrator privileges for the web-based service portal of the affected software. This vulnerability affects Cisco Elastic Services Controller Software Release 3.0.0. Cisco Bug IDs: CSCvg29809.Show less
1Hp
1System Management Homepage
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.6 MEDIUM· v3
5.5 MEDIUM· v2
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
1Mod Nss Project
1Mod Nss
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and entering 'password' as the password.
1Huawei
1Duke L09 Firmware
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
The 'Find Phone' function in some Huawei smart phones with software earlier than Duke-L09C10B186 versions, earlier than Duke-L09C432B187 versions, earlier than Duke-L09C636B186 versions has an authentication bypass vulne...Show more
The 'Find Phone' function in some Huawei smart phones with software earlier than Duke-L09C10B186 versions, earlier than Duke-L09C432B187 versions, earlier than Duke-L09C636B186 versions has an authentication bypass vulnerability. Due to improper authentication realization in the 'Find Phone' function. An attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.Show less
1Huawei
1Honor V9 Play Firmware
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerability. Due to improper authentication realization in the 'Find Phone' func...Show more
The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerability. Due to improper authentication realization in the 'Find Phone' function. An attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.Show less