← Back
CWE-287

4,477 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,477)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Emc
1Networker
May 6, 2026
Jun 10, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.
1Trihedral
1Vtscada
May 6, 2026
Jun 9, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitrary files via unspecified vectors.
1Apache
1Qpid Broker J
May 6, 2026
Jun 1, 2016
N/A· v4
9.1 CRITICAL· v3
5.0 MEDIUM· v2
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state loggin...Show more
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.Show less
1Apache
1Qpid Broker J
May 6, 2026
Jun 1, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication at...Show more
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.Show less
1Moxa
5Miineport E1 4641 Firmware
Miineport E1 7080 FirmwareMiineport E2 1242 Firmware+2 more
May 6, 2026
May 31, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices wit...Show more
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 have a blank default password, which allows remote attackers to obtain access via unspecified vectors.Show less
1Cisco
1Identity Services Engine Software
May 6, 2026
May 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (au...Show more
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.Show less
1Hp
1Network Node Manager I
May 6, 2026
May 7, 2016
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors.
2Debian
Libpam Sshauth Project
2Debian Linux
Libpam Sshauth
May 6, 2026
May 6, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account.
1Cisco
1Telepresence Tc Software
May 6, 2026
May 5, 2016
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which al...Show more
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which allows remote attackers to execute control commands or make configuration changes via an API request, aka Bug ID CSCuz26935.Show less
1Ecava
1Integraxor
May 6, 2026
Apr 22, 2016
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.
1Vmware
3Vcenter Server
Vcloud Automation Identity ApplianceVcloud Director
May 6, 2026
Apr 15, 2016
N/A· v4
7.6 HIGH· v3
6.8 MEDIUM· v2
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which a...Show more
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.Show less
1Apache
1Ranger
May 6, 2026
Apr 12, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username.
1Hp
1Support Assistant
May 6, 2026
Mar 19, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.
1Cisco
1Firesight System Software
May 6, 2026
Mar 3, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID...Show more
Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.Show less
4Samsung
SunZyxel+1 more
4Gs1900 10hp Firmware
Keymouse FirmwareOpensolaris+1 more
May 6, 2026
Mar 3, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileg...Show more
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.Show less
2Zyxel
Zzinc
2Gs1900 10hp Firmware
Keymouse Firmware
May 6, 2026
Feb 7, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bu...Show more
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.Show less
1Sauter
1Moduweb Vision
May 6, 2026
Feb 6, 2016
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password.
1Fisher Price
1Smart Toy Bear
May 6, 2026
Feb 4, 2016
N/A· v4
7.5 HIGH· v3
6.5 MEDIUM· v2
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number.
3Canonical
DebianHaxx
3Curl
Debian LinuxUbuntu Linux
May 6, 2026
Jan 29, 2016
N/A· v4
7.3 HIGH· v3
5.0 MEDIUM· v2
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a simila...Show more
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.Show less
1Apache
1Hive
May 6, 2026
Jan 29, 2016
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions vi...Show more
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.Show less