Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrai
Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access t
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift
This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadO
A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part
CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someon
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unau
Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authentica
A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.aut
Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protecte
VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with phy
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validi
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity p
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is prov
An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physic
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a
Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or admini
Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to acce
Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This is
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A3
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two
Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOK
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability coul
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability th
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configur
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually cam
An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 befor
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode with
A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the
An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos
Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker t
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authenti
symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security co
Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the V
An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, m
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On
Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypa
An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the devic
CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malic
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started