← Back
CWE-287

4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
14Sinamics G110
Sinamics G110dSinamics G120+11 more
Apr 29, 2026
Dec 7, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21...Show more
Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.Show less
1Google
1Chrome
Apr 29, 2026
Dec 7, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to...Show more
The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.Show less
1Sybase
1Adaptive Server Enterprise
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
8.5 HIGH· v2
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 does not properly perform authorization, which allows remote authenticated users to gai...Show more
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 does not properly perform authorization, which allows remote authenticated users to gain privileges via unspecified vectors.Show less
1Pineapp
1Mail Secure
Apr 29, 2026
Nov 20, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it parameter.
1Saltstack
1Salt
Apr 29, 2026
Nov 5, 2013
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.
1Novell
1Zenworks Configuration Management
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.
1Juniper
1Junos
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
8.5 HIGH· v2
Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configuration validation errors during the config commit phase of the boot-up seq...Show more
Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configuration validation errors during the config commit phase of the boot-up sequence, which allows remote attackers to bypass authentication via unspecified vectors.Show less
1Redhat
1Jboss Enterprise Portal Platform
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive informati...Show more
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.Show less
1Puppet
1Puppet Enterprise
Apr 29, 2026
Oct 25, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force at...Show more
Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force attack.Show less
1Cisco
1Identity Services Engine Software
Apr 29, 2026
Oct 25, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty2...Show more
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.Show less
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8....Show more
The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.6) does not properly implement the authentication-certificate option, which allows remote attackers to bypass authentication via a TCP session to an ASDM interface, aka Bug ID CSCuh44815.Show less
1Cisco
1Adaptive Security Appliance Software
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3...Show more
The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.5), when an override-account-disable option is enabled, does not properly parse AAA LDAP responses, which allows remote attackers to bypass authentication via a VPN connection attempt, aka Bug ID CSCug83401.Show less
1Hp
2Imc Service Operation Management Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.
1Asus
2Rt N10e
Rt N10e Firmware
Apr 29, 2026
Oct 5, 2013
N/A· v4
N/A· v3
6.1 MEDIUM· v2
qis/QIS_finish.htm on the ASUS RT-N10E router with firmware before 2.0.0.25 does not require authentication, which allows remote attackers to discover the administrator password via a direct request.
1Apple
1Mac Os X
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Directory Services in Apple Mac OS X before 10.8.5 Supplemental Update allows local users to bypass password-based authentication and modify arbitrary Directory Services records via unspecified vectors.
1Siemens
3Scalance X 200
Scalance X 200 Series FirmwareScalance X 200irt
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attacker...Show more
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.Show less
1Cisco
1Video Surveillance Operations Manager
Apr 29, 2026
Sep 30, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262.
1Open Xchange
1Open Xchange Appsuite
Apr 29, 2026
Sep 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The (1) REST and (2) memcache interfaces in the Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 do not require authentication, which allows remote attackers to obtain...Show more
The (1) REST and (2) memcache interfaces in the Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 do not require authentication, which allows remote attackers to obtain sensitive information or modify data via an API call.Show less
1Cisco
1Unified Computing System
Apr 29, 2026
Sep 24, 2013
N/A· v4
N/A· v3
8.5 HIGH· v2
The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SS...Show more
The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656.Show less
1Synacor
1Zimbra Collaboration Suite
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_AUTH_TOKEN token.