The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” fea
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused b
TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles,
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalat
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. I
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privile
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than
D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parame
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific au
An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to au
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional sof
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to a
Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POS
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Ci
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All ver
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI351
By using a specific credential string, an attacker with network access to the device’s web interface could circumvent th
Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been lo
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API r
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This in
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator crede
Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthen
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authentic
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request
Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unau
Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized acce
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the
OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentica
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session to
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism
A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the prod
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_acce
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started