pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) fro
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vul
D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks lead
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features t
In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager v
An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authenticatio
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Acti
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL
Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. Th
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could al
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A speci
Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unaut
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allo
An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute
Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability th
Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file wit
The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is
capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalati
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a v
An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll c
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on dep
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a r
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all aut
There is broken access control during authentication in Jamf Pro Server before 10.46.1.
Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and P
Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Fo
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has
Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Bus
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized
Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allo
Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when L
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n
An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacke
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.
maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a fu
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAM
`effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior t
Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue af
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAM
Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Feder
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started