A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow a
EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first fa
The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based manageme
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote un
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authent
libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPD
Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously u
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSess
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations:
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-19
Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wal
Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent at
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote use
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote use
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authenticati
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent una
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on
TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerabilit
Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary
Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a netwo
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentic
Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and
Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074,
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) ca
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successf
** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 thr
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They
An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00.
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry
Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified
Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated
Memory Corruption in Core due to secure memory access by user while loading modem image.
A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the defaul
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechan
NVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA i
ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 thr
Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exp
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of
JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting i
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticat
An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_4967
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. Duri
The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associate
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started