← Back
CWE-287

4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nongnu
1Oath Toolkit
May 6, 2026
Mar 9, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when inv...Show more
usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.Show less
1Puppet
1Puppet Enterprise
May 6, 2026
Mar 9, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a con...Show more
The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.Show less
1Foscam
2Fi8919w
Fi8919w Firmware
May 6, 2026
Mar 6, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The Foscam FI8910W camera with firmware before 11.37.2.55 allows remote attackers to obtain sensitive video and image data via a blank username and password.
1Tibco
2Enterprise Administrator
Enterprise Administrator Sdk
Apr 29, 2026
Feb 27, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authentication requirements, which allows remote attackers to execute arbitrary commands via unspecified...Show more
TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authentication requirements, which allows remote attackers to execute arbitrary commands via unspecified vectors.Show less
1Cisco
1Unified Communications Manager
Apr 29, 2026
Feb 27, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information...Show more
The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, aka Bug ID CSCum95468.Show less
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to unt...Show more
Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766.Show less
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL...Show more
The Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66770.Show less
1Cisco
1Unified Ip Phone 7960g
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795.
1Cisco
1Unified Communications Manager
Apr 29, 2026
Feb 20, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM fil...Show more
The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct request to a URL, aka Bug ID CSCum46494.Show less
1Cisco
1Unified Communications Manager
Apr 29, 2026
Feb 20, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read a...Show more
The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to a URL, aka Bug ID CSCum46495.Show less
1Redhat
1Jboss Operations Network
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based account...Show more
Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.Show less
1Redhat
1Jboss Operations Network
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
1Cisco
1Unified Communications Manager
Apr 29, 2026
Feb 13, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified access to a "file storage location," aka Bug...Show more
Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified access to a "file storage location," aka Bug ID CSCum05337.Show less
1Cisco
1Unified Communications Manager
Apr 29, 2026
Feb 13, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified...Show more
The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified use of this application, aka Bug ID CSCum05347.Show less
3Armin Burgmeier
OpensuseOracle
3Net6
OpensuseSolaris
Apr 29, 2026
Feb 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage p...Show more
The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.Show less
1Seowonintech
1Swc 9100
Apr 29, 2026
Feb 4, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a default_reboot action or (2) reset all configuration values via a factory_default action.
6Gatehouse
HarrisHughes Network Systems+3 more
99201
94509502+6 more
Apr 29, 2026
Feb 4, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require a...Show more
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary code via unspecified protocol operations.Show less
1Haxx
2Curl
Libcurl
Apr 29, 2026
Feb 2, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
2Brion Vibber
Mediawiki
2Centralauth Extension
Mediawiki
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logg...Show more
The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.Show less
1Burden Project
1Burden
Apr 29, 2026
Jan 26, 2014
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.