CWE-287
4,488 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,488)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server. |
TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resulting in the ability to disable arbitrary running splits and cause denial of service to clients in t...Show more |
1Oracle 1Glassfish Server May 13, 2026 Jul 17, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possible to provide an unauthenticated attacker plain text password of admini...Show more |
1Ecos 1Embedded Web Servers May 13, 2026 Jul 17, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending SYN Flood or FIN Flood...Show more |
1Ibm 1Emptoris Strategic Supply Management May 13, 2026 Jul 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vulnerability in the authentication features that could log out users and...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Jul 11, 2017 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extende...Show more |
It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (but TLS is not). If t...Show more |
Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a mali...Show more |
1Siemens 1Simatic Cp 44x 1 Redundant Network Access Modules May 13, 2026 Jul 7, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may be able to perform administrative actions on the Communication Process...Show more |
HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to bypass authentication to load malicious firmware via WebUI. |
On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the IP address belonging to the victim's host, an attacker might be able t...Show more |
1Cisco 1Ultra Services Framework May 13, 2026 Jul 6, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. The vulnerability is due to an...Show more |
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739. |
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685 |
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled. |
1Cisco 1Unified Contact Center Express May 13, 2026 Jul 4, 2017 N/A· v4 6.1 MEDIUM· v3 5.5 MEDIUM· v2 A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Cl...Show more |
1Cisco 1Prime Collaboration Provisioning May 13, 2026 Jul 4, 2017 N/A· v4 5.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack another user's session. More Information: CSCvc90346. Known Affected Rel...Show more |
1Newport 2Xps Cx Firmware Xps Qx FirmwareMay 13, 2026 Jul 3, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific uniform resource locator (URL). |
On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL. |
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess. |