CWE-287
4,488 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,488)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform...Show more |
1Siemens 2Simatic Wincc Sm@rtclient Simatic Wincc Sm@rtclient LiteMay 13, 2026 Aug 8, 2017 N/A· v4 5.4 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical acce...Show more |
1Siemens 1Viewport For Web Office Portal May 13, 2026 Aug 8, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the ope...Show more |
3Debian NetappNtp7Clustered Data Ontap Data OntapDebian Linux+4 moreMay 13, 2026 Aug 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. |
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authenticat...Show more |
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issu...Show more |
1Pdqinc 11Laserjet Firmware Laserwash 360 FirmwareLaserwash 360 Plus Firmware+8 moreMay 13, 2026 Aug 7, 2017 N/A· v4 9.4 CRITICAL· v3 7.5 HIGH· v2 An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress P...Show more |
1Abb 2Vsn300 Firmware Vsn300 For React FirmwareMay 13, 2026 Aug 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (...Show more |
1Cisco 1Identity Services Engine May 13, 2026 Aug 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authen...Show more |
1Sma 39Sunny Boy 1.5 Firmware Sunny Boy 2.5 FirmwareSunny Boy 3.0 Firmware+36 moreMay 13, 2026 Aug 5, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device firmware without ever having to authenticate. If an attacker is able to...Show more |
1Sma 39Sunny Boy 1.5 Firmware Sunny Boy 2.5 FirmwareSunny Boy 3.0 Firmware+36 moreMay 13, 2026 Aug 5, 2017 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet injection, and replay att...Show more |
MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server. |
MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control" is installed) allow remote attackers to bypass authentication to execute arbitr...Show more |
1Comcast 1Xfinity Wifi Hotspot May 13, 2026 Jul 31, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Comcast XFINITY WiFi Home Hotspot devices allow remote attackers to spoof the identities of Comcast customers via a forged MAC address. |
1Netcomm 24gt101w Bootloader 4gt101w SoftwareMay 13, 2026 Jul 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 do not require authentication for logfile.html, status.html, or system_config.html. |
1Buffalo 2Wapm 1166d Firmware Wapm Apg600h FirmwareMay 13, 2026 Jul 22, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access the configuration interface via unspecified vectors. |
1Televes 1Coaxdata Gateway 1gbps Firmware May 13, 2026 Jul 20, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 do not check password.shtml authorization, leading to Arbitrary password change. |
1Emc 1Rsa Authentication Manager May 13, 2026 Jul 17, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that...Show more |
An insufficient authentication vulnerability on platforms where Junos OS instances are run in a virtualized environment, may allow unprivileged users on the Junos OS instance to gain access to the host operating environm...Show more |
A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without being prompted for a password while trying to login through console, ssh, ftp, telnet or su, etc., T...Show more |