← Back
CWE-287

4,483 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,483)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ipa
1Appgoat
May 13, 2026
Apr 28, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arbitrary operations via unspecified vectors.
1Wificam
1Wireless Ip Camera (p2p) Firmware
May 13, 2026
Apr 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0.
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged...Show more
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged actions to gain complete control over the environment.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivile...Show more
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivileged system files capable of causing widespread denials of system services.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, lea...Show more
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, leading to managed systems being compromised or services being denied to authentic end users and systems as a result.Show less
1Tp Link
1Tl Sg108e Firmware
May 13, 2026
Apr 23, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
1Cisco
1Integrated Management Controller Supervisor
May 13, 2026
Apr 20, 2017
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user s...Show more
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not assign a new session identifier to a user session when a user authenticates to the web-based GUI. An attacker could exploit this vulnerability by using a hijacked session identifier to connect to the software through the web-based GUI. A successful exploit could allow the attacker to hijack an authenticated user's browser session on the affected system. Cisco Bug IDs: CSCvd14583.Show less
1Cybozu
1Garoon
May 13, 2026
Apr 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.
2Firewalld
Redhat
5Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+2 more
May 13, 2026
Apr 19, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries...Show more
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.Show less
1Unitrends
1Enterprise Backup
May 13, 2026
Apr 12, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This...Show more
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.Show less
1Brother
4Ads Firmware
Dcp FirmwareHl Firmware+1 more
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L885...Show more
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.Show less
4Debian
OpenbsdOracle+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+6 more
May 29, 2026
Apr 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and...Show more
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SECURITY extension on this X11 server.Show less
1Sierrawireless
1Aleos Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.
1Trendnet
1Tv Ip743sic
May 13, 2026
Apr 10, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.
1Dataprobe
1Ibootbar Firmware
May 13, 2026
Apr 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCCOOKIE cookie.
1Dataprobe
1Ibootbar Firmware
May 13, 2026
Apr 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCRABBIT cookie.
1Airtame
1Hdmi Dongle Firmware
May 13, 2026
Apr 5, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all information including the Wi-Fi password, reboot, or force a software...Show more
AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all information including the Wi-Fi password, reboot, or force a software update at an arbitrary time.Show less
1Ceragon
1Fibeair Ip 10 Firmware
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.
1Siemens
1Ruggedcom Rox I
May 13, 2026
Mar 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration settings.
2Nextcloud
Owncloud
2Nextcloud Server
Owncloud
May 13, 2026
Mar 28, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication...Show more
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticating users against an SMB server. This backend is implemented in a way that tries to connect to a SMB server and if that succeeded consider the user logged-in. The backend did not properly take into account SMB servers that have any kind of anonymous auth configured. This is the default on SMB servers nowadays and allows an unauthenticated attacker to gain access to an account without valid credentials. Note: The SMB backend is disabled by default and requires manual configuration in the Nextcloud/ownCloud config file. If you have not configured the SMB backend then you're not affected by this vulnerability.Show less