There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a vali
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentia
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent
There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successf
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH co
Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acron
Windows Power Management Service Information Disclosure Vulnerability
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via netwo
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obta
Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permission
Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially e
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be pos
Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in t
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH s
Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass auth
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass aut
A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vu
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versio
m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenti
It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT to
Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and ea
A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used i
A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS al
An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allo
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all ve
Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a rem
The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful
Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries w
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an ins
Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to aut
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations cou
Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created accou
An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint actio
The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due
An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attack
An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 2023040
Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at le
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitiv
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using t
Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, an
Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, a
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX acti
The firmware update package for the wireless card is not properly signed and can be modified.
Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper p
Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to c
Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in cont
matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 a
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started