← Back
CWE-287

4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Djangoproject
1Django
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password...Show more
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.Show less
1Cisco
1Prime Central For Hosted Collaboration Solution Assurance
Apr 29, 2026
Sep 20, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover use...Show more
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.Show less
1Cisco
1Intrusion Prevention System
Apr 29, 2026
Sep 19, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp ha...Show more
The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted management-interface connection request, aka Bug ID CSCuf20148.Show less
1Dahuasecurity
65Dvr0404hd A
Dvr0404hd LDvr0404hd S+62 more
Apr 29, 2026
Sep 17, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.
1Ibm
1Rational Requirements Composer
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
5.4 MEDIUM· v2
IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.
1Ibm
1Rational Policy Tester
Apr 29, 2026
Sep 9, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP re...Show more
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP redirect via unspecified vectors.Show less
1Paloaltonetworks
1Pan Os
Apr 29, 2026
Aug 31, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors,...Show more
The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors, aka Ref ID 37034.Show less
1Cisco
1Secure Access Control Server
Apr 29, 2026
Aug 29, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers...Show more
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.Show less
1Samsung
2Dvr
Smart Viewer
Apr 29, 2026
Aug 28, 2013
N/A· v4
N/A· v3
7.6 HIGH· v2
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.
1Puppet
1Puppet Enterprise
Apr 29, 2026
Aug 20, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation.
1Openstack
1Keystone
Apr 29, 2026
Aug 20, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
1Nttdocomo
1Overseas Usage
Apr 29, 2026
Aug 9, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.1...Show more
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverage area.Show less
1Ibm
1Websphere Commerce
Apr 29, 2026
Aug 1, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary us...Show more
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown vectors.Show less
1Redhat
1Satellite
Apr 29, 2026
Jul 31, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial...Show more
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.Show less
1Moodle
1Moodle
Apr 29, 2026
Jul 29, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenti...Show more
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.Show less
1Cisco
1Video Surveillance Manager
Apr 29, 2026
Jul 25, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via u...Show more
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169.Show less
1Cisco
1Video Surveillance Manager
Apr 29, 2026
Jul 25, 2013
N/A· v4
N/A· v3
9.0 HIGH· v2
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code)...Show more
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288.Show less
1Cybozu
1Cybozu Office
Apr 29, 2026
Jul 20, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.
1Verizon
1Wireless Network Extender
Apr 29, 2026
Jul 18, 2013
N/A· v4
N/A· v3
2.6 LOW· v2
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, b...Show more
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the network for registration packets.Show less
1Verizon
1Wireless Network Extender
Apr 29, 2026
Jul 18, 2013
N/A· v4
N/A· v3
6.2 MEDIUM· v2
The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and obtain a login prompt by connecting a crafted HDMI cable and sending a...Show more
The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and obtain a login prompt by connecting a crafted HDMI cable and sending a SysReq interrupt.Show less