← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcafee
1Linuxshield
Apr 29, 2026
Aug 22, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin access to the statistics server by leveraging a client account.
1Gnome
1Libsoup
Apr 29, 2026
Aug 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.
1Tridium
1Niagara Ax
Apr 29, 2026
Aug 16, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Tridium Niagara AX Framework through 3.6 uses predictable values for (1) session IDs and (2) keys, which might allow remote attackers to bypass authentication via a brute-force attack.
1Ushahidi
1Ushahidi Platform
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API fu...Show more
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.Show less
1Ushahidi
1Ushahidi Platform
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET reques...Show more
The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET request.Show less
1Breakingpointsystems
2Breakingpoint Storm Appliance
Breakingpoint Storm Appliance Ctm
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive info...Show more
The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/BugReport script, which allows remote attackers to obtain sensitive information by downloading a .tgz file.Show less
1Rubyonrails
2Rails
Ruby On Rails
Apr 29, 2026
Aug 8, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symb...Show more
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an application that uses a with_http_digest helper method, as demonstrated by the authenticate_or_request_with_http_digest method.Show less
1Cisco
1Anyconnect Secure Mobility Client
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a craft...Show more
Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.Show less
2Puppet
Puppetlabs
2Puppet
Puppet Enterprise
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote attackers to spoof an ag...Show more
lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote attackers to spoof an agent by acquiring a previously used IP address.Show less
1Sonicwall
1Scrutinizer
Apr 29, 2026
Jul 31, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs...Show more
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.Show less
1Airdroid
1Airdroid
Apr 29, 2026
Jul 26, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to obtain access via a brute-force attack.
1Airdroid
1Airdroid
Apr 29, 2026
Jul 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to obtain access by sniffing the local wireless network and then replayin...Show more
AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to obtain access by sniffing the local wireless network and then replaying the authentication data.Show less
1Viewvc
1Viewvc
Apr 29, 2026
Jul 22, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
1Moodle
1Moodle
Apr 29, 2026
Jul 20, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated us...Show more
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.Show less
1Smc
1Smc8024l2 Switch
Apr 29, 2026
Jul 19, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request to a .html file under (1) status/, (2) system/, (3) ports/, (4) trunks/...Show more
The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request to a .html file under (1) status/, (2) system/, (3) ports/, (4) trunks/, (5) vlans/, (6) qos/, (7) rstp/, (8) dot1x/, (9) security/, (10) igmps/, or (11) snmp/.Show less
2Debian
Mahara
2Debian Linux
Mahara
Apr 29, 2026
Jul 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP serve...Show more
The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.Show less
1Symantec
1Message Filter
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
5.4 MEDIUM· v2
Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspecified vectors.
1Rsa
2Access Manager Agent
Access Manager Server
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
EMC RSA Access Manager Server 6.x before 6.1 SP4 and RSA Access Manager Agent do not properly validate session tokens after a logout, which might allow remote attackers to conduct replay attacks via unspecified vectors.
1Mantisbt
1Mantisbt
Apr 29, 2026
Jun 29, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authentication via a null password.
1Strongswan
1Strongswan
Apr 29, 2026
Jun 27, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."