Windows Kerberos Security Feature Bypass Vulnerability
Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability wil
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind
Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Prop
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a u
Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authenti
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authen
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could resu
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Du
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a p
**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version
Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows
IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority req
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of th
A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affec
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector o
A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical
there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privi
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starti
A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects
fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth su
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second fa
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This is
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.
An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and ol
A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a s
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perfo
The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all vers
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an admin
IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate conne
Microsoft Authenticator Elevation of Privilege Vulnerability
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fai
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission
OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attacke
An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attac
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privi
An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerabilit
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7
IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and
Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is
Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to c
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_sup
IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started