CWE-287
4,483 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,483)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arbitrary operations via unspecified vectors. |
1Wificam 1Wireless Ip Camera (p2p) Firmware May 13, 2026 Apr 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0. |
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged...Show more |
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivile...Show more |
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, lea...Show more |
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017 Rel.50749 firmware. |
1Cisco 1Integrated Management Controller Supervisor May 13, 2026 Apr 20, 2017 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user s...Show more |
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. |
2Firewalld Redhat5Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+2 moreMay 13, 2026 Apr 19, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries...Show more |
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This...Show more |
1Brother 4Ads Firmware Dcp FirmwareHl Firmware+1 moreMay 13, 2026 Apr 12, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L885...Show more |
4Debian OpenbsdOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 29, 2026 Apr 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and...Show more |
1Sierrawireless 1Aleos Firmware May 13, 2026 Apr 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests. |
TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account. |
Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCCOOKIE cookie. |
Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCRABBIT cookie. |
1Airtame 1Hdmi Dongle Firmware May 13, 2026 Apr 5, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all information including the Wi-Fi password, reboot, or force a software...Show more |
1Ceragon 1Fibeair Ip 10 Firmware May 13, 2026 Mar 30, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser. |
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration settings. |
2Nextcloud Owncloud2Nextcloud Server OwncloudMay 13, 2026 Mar 28, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication...Show more |