An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache
The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to th
Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify d
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability du
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2,
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and bel
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Iden
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS use
Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker coul
The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to
Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive info
Windows Kerberos Elevation of Privilege Vulnerability
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. At
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communicati
An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypa
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor t
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u
strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe
The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful
Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access conte
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authenticatio
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be f
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench
Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via se
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may af
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but s
An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentic
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.0
In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic erro
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login pro
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macO
D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.
Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Prot
Transient DOS due to improper authorization in Modem
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to sen
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnera
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnera
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incor
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Pr
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started