An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to a
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devi
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the
Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Editio
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive infor
A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vul
An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.1
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is s
Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user ca
Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerabi
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method`
An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 b
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong en
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mod
A vulnerability, which was classified as critical, was found in holdennb CollabCal. Affected is the function handleGet o
A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issu
A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is
A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affec
A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is s
A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of
An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and key
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue af
Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification
In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allo
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a l
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network acces
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Co
A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password
In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to lo
The configuration from the PCU can be modified without authentication using physical connection to the PCU.
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability h
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0.
Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user
Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windo
Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation soft
NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process
The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerabilit
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started