← Back
CWE-287

4,475 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,475)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aptexx
1Resident Anywhere
May 6, 2026
Jun 23, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Aptexx Resident Anywhere does not require authentication, which allows remote attackers to obtain sensitive information or modify data via a direct request.
1Magento
1Magento
May 6, 2026
Apr 29, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.
1Hp
2Tippingpoint Security Management System
Tippingpoint Virtual Security Management System
May 6, 2026
Apr 27, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1 do not require authentication for JBoss RMI requests, which allows rem...Show more
HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1 do not require authentication for JBoss RMI requests, which allows remote attackers to execute arbitrary code by (1) uploading this code within an archive or (2) instantiating a class.Show less
1Siemens
1Wincc
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd...Show more
Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Professional before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal), SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal), SIMATIC HMI Multi Panels (WinCC TIA Portal), and SIMATIC WinCC 7.x before 7.3 Upd4 allow remote attackers to complete authentication by leveraging knowledge of a password hash without knowledge of the associated password.Show less
1Ibm
1General Parallel File System
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary program...Show more
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors.Show less
1Cisco
15Spa300 Firmware
Spa500 FirmwareSpa 301 1 Line Ip Phone+12 more
May 6, 2026
Mar 21, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls v...Show more
The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482.Show less
1Cisco
3Expressway Software
Telepresence ConductorTelepresence Video Communication Server Software
May 6, 2026
Mar 13, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before...Show more
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.Show less
1Cisco
1Ios
May 6, 2026
Mar 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a...Show more
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.Show less
2Debian
Typo3
2Debian Linux
Typo3
May 6, 2026
Feb 23, 2015
N/A· v4
N/A· v3
2.6 LOW· v2
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password...Show more
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value.Show less
1Infoblox
1Netmri
May 6, 2026
Feb 20, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Anyterm Daemon in Infoblox Network Automation NetMRI before NETMRI-23483 allows remote attackers to execute arbitrary commands with root privileges via a crafted terminal/anyterm-module request.
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requirements via a crafted password.
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to bypass authentication via a null byte in the password and a valid u...Show more
The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to bypass authentication via a null byte in the password and a valid user name, which triggers an unauthenticated bind.Show less
1Cisco
1Webex Meetings Server
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.
1Vdgsecurity
1Vdg Sense
May 6, 2026
Jan 8, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.
1Umbraco
1Umbraco Cms
May 6, 2026
Dec 27, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP...Show more
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.Show less
1Ibm
2Infosphere Master Data Management Collaborative Server
Infosphere Master Data Management Server For Product Information Management
May 6, 2026
Dec 22, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7...Show more
The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify the administrator's credentials and consequently gain privileges via unspecified vectors.Show less
1Cisco
1Isb8320 E High Definition Ip Only Dvr
May 6, 2026
Dec 17, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422.
1Hp
1Hp Ux
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
8.5 HIGH· v2
HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication, and consequently execute arbitrary code, via unspecified vectors.
1Apache
1Cloudstack
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
1Torch Gmbh
1Graylog2
May 6, 2026
Dec 8, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.