← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rsa
1Envision
Apr 29, 2026
Mar 20, 2012
N/A· v4
N/A· v3
7.9 HIGH· v2
EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
1Easyvista
1Easyvista
Apr 29, 2026
Feb 22, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a valid login name in the SSPI_HEADER par...Show more
The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a valid login name in the SSPI_HEADER parameter, to index.php.Show less
1Advantech
1Advantech Webaccess
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.
1Advantech
1Advantech Webaccess
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.
1Siemens
5Simatic Hmi Panels
WinccWincc Flexible+2 more
Apr 29, 2026
Feb 3, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Run...Show more
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authentication, which makes it easier for remote attackers to obtain access via a TCP session.Show less
1Siemens
5Simatic Hmi Panels
WinccWincc Flexible+2 more
Apr 29, 2026
Feb 3, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime...Show more
The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime generates predictable authentication tokens for cookies, which makes it easier for remote attackers to bypass authentication via a crafted cookie.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Feb 2, 2012
N/A· v4
N/A· v3
7.2 HIGH· v2
WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by leveraging access to (1) the server or (2) a bound directory.
1Schneider Electric
1Modicon Quantum Plc
Apr 29, 2026
Jan 28, 2012
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vec...Show more
Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.Show less
1Symantec
1Pcanywhere
Apr 29, 2026
Jan 25, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which a...Show more
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute arbitrary code via a crafted session on TCP port 5631.Show less
1Apache
1Tomcat
Apr 29, 2026
Jan 14, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended acces...Show more
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.Show less
1Kde
1Kcheckpass
Apr 29, 2026
Jan 6, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an a...Show more
kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an arbitrary valid PAM service name, a different vulnerability than CVE-2011-4122. NOTE: the vendor indicates that the possibility of resultant privilege escalation may be "a bit far-fetched."Show less
1Wi Fi
1Wifi Protected Setup Protocol
Apr 29, 2026
Jan 6, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to disco...Show more
The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access point, by reading EAP-NACK messages.Show less
1Splunk
1Splunk
Apr 29, 2026
Jan 3, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read...Show more
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-console session that leverages the ability to create crafted data sources, or (2) execute management commands via an HTTP request.Show less
1Mozilla
1Bugzilla
Apr 29, 2026
Jan 2, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not...Show more
The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.Show less
1Cyrus
1Imapd
Apr 29, 2026
Dec 24, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
1Schneider Electric
3Quantum Ethernet Module 140noe77100
Quantum Ethernet Module 140noe77101Quantum Ethernet Module 140noe77111
Apr 29, 2026
Dec 17, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the...Show more
The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.Show less
1Oneclickorgs
1One Click Orgs
Apr 29, 2026
Dec 6, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
1Indusoft
1Web Studio
Apr 29, 2026
Dec 5, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creatio...Show more
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.Show less
1Ibm
4Ts3100 Tape Library
Ts3100 Tape Library FirmwareTs3200 Tape Library+1 more
Apr 29, 2026
Nov 28, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.
1Opengear
7Acm5000 Console Server
Cm4000 Console ServerIm4004 5 Console Server+4 more
Apr 29, 2026
Nov 9, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings or access connected equipment, via unspecified vectors.