RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to c
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softb
MegaRAC Default Credentials Vulnerability
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text dur
Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authenticatio
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access r
Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are
Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a m
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U
Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a
A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentica
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the ta
A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-au
Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Clou
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensiti
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providi
Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.
An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a ma
The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts i
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated use
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code executi
A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP
otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces
Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process commun
Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnera
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found i
Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authen
TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Un
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS i
Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated
A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are grant
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to
Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, I
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application s
An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by chan
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `i
An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attack
A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and co
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started