softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass
platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulne
A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correc
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an
Microsoft OneNote Elevation of Privilege Vulnerability
This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, whi
A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This a
Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to c
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to M
The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid param
Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From version
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_
Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows unti
Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attack
ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.
Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2,
Walchem Intuition 9 firmware versions prior to v4.21 are vulnerable to improper authentication. Login credentials are st
PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests
Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to acce
A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range o
An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthe
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, h
Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a u
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Pr
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial o
Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the
A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability i
A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been declared as critical. Affected by this vulner
A vulnerability classified as critical has been found in SATO CL4NX-J Plus 1.13.2-u455_r2. This affects an unknown part
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encry
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 11002
A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypa
Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account informa
Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass r
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User ac
Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u
Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of un
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in w
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously
A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attac
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attack
Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password prote
A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown fun
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a fa
Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started