CWE-287
4,477 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,477)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance. |
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitrary files via unspecified vectors. |
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state loggin...Show more |
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication at...Show more |
1Moxa 5Miineport E1 4641 Firmware Miineport E1 7080 FirmwareMiineport E2 1242 Firmware+2 moreMay 6, 2026 May 31, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices wit...Show more |
1Cisco 1Identity Services Engine Software May 6, 2026 May 21, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (au...Show more |
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors. |
2Debian Libpam Sshauth Project2Debian Linux Libpam SshauthMay 6, 2026 May 6, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account. |
1Cisco 1Telepresence Tc Software May 6, 2026 May 5, 2016 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which al...Show more |
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors. |
1Vmware 3Vcenter Server Vcloud Automation Identity ApplianceVcloud DirectorMay 6, 2026 Apr 15, 2016 N/A· v4 7.6 HIGH· v3 6.8 MEDIUM· v2 Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which a...Show more |
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username. |
HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors. |
Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID...Show more |
4Samsung SunZyxel+1 more4Gs1900 10hp Firmware Keymouse FirmwareOpensolaris+1 moreMay 6, 2026 Mar 3, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileg...Show more |
2Zyxel Zzinc2Gs1900 10hp Firmware Keymouse FirmwareMay 6, 2026 Feb 7, 2016 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bu...Show more |
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password. |
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number. |
3Canonical DebianHaxx3Curl Debian LinuxUbuntu LinuxMay 6, 2026 Jan 29, 2016 N/A· v4 7.3 HIGH· v3 5.0 MEDIUM· v2 The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a simila...Show more |
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions vi...Show more |