← Back
CWE-287

4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Hadoop
Apr 29, 2026
Jan 24, 2014
N/A· v4
N/A· v3
3.2 LOW· v2
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirect...Show more
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.Show less
1Cisco
1Video Surveillance Operations Manager
Apr 29, 2026
Jan 24, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service...Show more
Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from a client system with a crafted host name, aka Bug ID CSCud10992.Show less
1Ibm
1Tivoli Federated Identity Manager
Apr 29, 2026
Jan 21, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Pas...Show more
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.Show less
3Debian
GoogleOpensuse
3Chrome
Debian LinuxOpensuse
Apr 29, 2026
Jan 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers...Show more
The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog.Show less
1Sierrawireless
19Airlink Mp At&t
Airlink Mp At&t WifiAirlink Mp Bell+16 more
Apr 29, 2026
Jan 15, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.
1Memcached
1Memcached
Apr 29, 2026
Jan 13, 2014
N/A· v4
N/A· v3
4.8 MEDIUM· v2
memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending another request with incorrect SASL credentials.
1Vasco
1Identikey Authentication Server
Apr 29, 2026
Jan 13, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of thi...Show more
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-time AD password.Show less
1Symantec
1Endpoint Protection
Apr 29, 2026
Jan 10, 2014
N/A· v4
N/A· v3
7.4 HIGH· v2
The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly perform authentication,...Show more
The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly perform authentication, which allows remote authenticated users to gain privileges by leveraging access to a limited-admin account.Show less
1Nisuta
4Ns Wir150ne
Ns Wir150ne FirmwareNs Wir300n+1 more
Apr 29, 2026
Jan 10, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows remote attackers to bypass authentication via a "Cookie: :language=en" H...Show more
The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows remote attackers to bypass authentication via a "Cookie: :language=en" HTTP header.Show less
1Hot
2Hotbox Router
Hotbox Router Firmware
Apr 29, 2026
Dec 30, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.
1Cybozu
1Garoon
Apr 29, 2026
Dec 28, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.
1Cisco
1Ios Xe
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging acc...Show more
The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.Show less
3Debian
FedoraprojectPhil Schwartz
3Debian Linux
DenyhostsFedora
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.
1Redhat
1Subscription Asset Manager
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.
1Ibm
2Sterling B2b Integrator
Sterling File Gateway
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
1Ibm
2Infosphere Master Data Management Collaboration Server
Infosphere Master Data Management Server For Product Information Management
Apr 29, 2026
Dec 19, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x...Show more
Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors.Show less
1Ibm
1Cognos Command Center
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.
1Zabbix
1Zabbix
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
1Sap
1Network Interface Router
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vectors.
1Dovecot
1Dovecot
Apr 29, 2026
Dec 9, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and...Show more
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.Show less