← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
4Telepresence Multipoint Switch
Telepresence Multipoint Switch SoftwareTelepresence Recording Server+1 more
Apr 29, 2026
Feb 25, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not req...Show more
The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug IDs CSCtf42005 and CSCtf42008.Show less
1Cisco
1Telepresence Manager
Apr 29, 2026
Feb 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.
1F Secure
1Internet Gatekeeper
Apr 29, 2026
Feb 18, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obtain potentially sensitive information via a TCP session on the admin UI...Show more
F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obtain potentially sensitive information via a TCP session on the admin UI port.Show less
1Microsoft
2Windows 7
Windows Server 2008
Apr 29, 2026
Feb 10, 2011
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain s...Show more
Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."Show less
1Microsoft
2Windows 2003 Server
Windows Xp
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request...Show more
The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."Show less
1Ibm
1Lotus Domino
Apr 29, 2026
Feb 8, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors,...Show more
The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors, aka SPR PRAD89WGRS.Show less
1Symantec
3Antivirus
Antivirus Central Quarantine ServerSystem Center
Apr 29, 2026
Jan 31, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote...Show more
Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary commands via crafted messages over TCP, as discovered by Junaid Bohio, a different vulnerability than CVE-2010-0110 and CVE-2010-0111. NOTE: some of these details are obtained from third party information.Show less
1Objectivity
1Objectivity/db
Apr 29, 2026
Jan 18, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data, obtain sensitive information, or cause a denial of service by sending...Show more
The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data, obtain sensitive information, or cause a denial of service by sending requests over TCP to (1) the Lock Server or (2) the Advanced Multithreaded Server, as demonstrated by commands that are ordinarily sent by the (a) ookillls and (b) oostopams applications. NOTE: some of these details are obtained from third party information.Show less
1Cisco
35500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly authenticate HTTP requests from a Web Security appliance (WSA), which m...Show more
The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly authenticate HTTP requests from a Web Security appliance (WSA), which might allow remote attackers to obtain sensitive information via a HEAD request, aka Bug ID CSCte53635.Show less
1Ibm
1Lotus Mobile Connect
Apr 29, 2026
Dec 22, 2010
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physica...Show more
The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.Show less
1Vmware
1Esxi
Apr 29, 2026
Dec 22, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and passwor...Show more
The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.Show less
1Eucalyptus
1Eucalyptus
Apr 29, 2026
Dec 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sending password reset requests for other user...Show more
The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sending password reset requests for other users.Show less
1Pangramsoft
1Pointter Php Micro Blogging Social Network
Apr 29, 2026
Dec 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.
1Pangramsoft
1Pointter Php Content Management System
Apr 29, 2026
Dec 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.
1Phpmyadmin
1Phpmyadmin
Apr 29, 2026
Dec 17, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.
1Google
1Chrome
Apr 29, 2026
Dec 7, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
1Openbsd
1Openssh
May 28, 2026
Dec 6, 2010
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfu...Show more
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.Show less
1Openssl
1Openssl
Apr 29, 2026
Dec 6, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfull...Show more
OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol.Show less
1Artica
1Pandora Fms
Apr 29, 2026
Dec 2, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the...Show more
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.Show less
1Redhat
2Certificate System
Dogtag Certificate System
Apr 29, 2026
Nov 17, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for...Show more
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.Show less