NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sendi
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatc
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock
Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible t
Unauthorized access to Gateway user capabilities
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with netwo
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with
UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerabi
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordP
A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechani
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a
Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can
An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthen
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A r
Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process
Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with
authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 20
A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaC
Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto,
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulner
Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page ca
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U
Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM)
Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer fro
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder AP
An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the U
Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabl
XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML respon
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthentic
Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started