CWE-287
4,477 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,477)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Secure Firewall Management Center May 6, 2026 Oct 6, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370. |
1Animas 1Onetouch Ping Firmware May 6, 2026 Oct 5, 2016 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol. |
1Animas 1Onetouch Ping Firmware May 6, 2026 Oct 5, 2016 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks. |
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded...Show more |
1Microsoft 1Azure Active Directory Passport May 6, 2026 Sep 28, 2016 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authe...Show more |
The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and obtain administrative access by sending "special packages" to the LAN...Show more |
The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter. |
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop...Show more |
1Pivotal Software 1Operations Manager May 6, 2026 Sep 18, 2016 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication b...Show more |
J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 13.3R10, 13.3R9 before 13.3R9-S1, 14.1 before 14.1R7, 14.1X53 before 14....Show more |
1Siemens 1En100 Ethernet Module Firmware May 6, 2026 Sep 6, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant D...Show more |
1Siemens 1En100 Ethernet Module Firmware May 6, 2026 Sep 6, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant D...Show more |
1Cisco 1Media Origination System Suite May 6, 2026 Sep 3, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and make arbitrary Platform and Applications Manager (PAM) API calls via unsp...Show more |
1Cisco 3Rv110w Wireless N Vpn Firewall Firmware Rv130w Wireless N Multifunction Vpn Router FirmwareRv215w Wireless N Vpn Router FirmwareMay 6, 2026 Aug 8, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCu...Show more |
Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a failed upgrade to 12.1X46, which might allow local users to gain privi...Show more |
Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a proxy-authentication login prompt or trigger incorrect credential storage b...Show more |
1Moxa 1Device Server Web Console 5232 N Firmware May 6, 2026 Jul 12, 2016 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors related to reading a cookie parameter containing a UserId value. |
5Ntp OpensuseOracle+2 more12Leap Linux Enterprise DesktopLinux Enterprise Server+9 moreMay 6, 2026 Jul 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time. |
The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remote attackers to obtain sensitive information via crafted SCP messages,...Show more |
Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access...Show more |