The device authentication service module has a defect vulnerability introduced in the design process.Successful exploita
Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerabilit
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vector
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to byp
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php an
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files wit
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 a
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake cred
An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaini
Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor cons
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact fo
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to a
A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (A
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scrip
Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log i
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, inclu
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the S
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection inf
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is no
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.
SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even
The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its set
An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious home
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating w
Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera
An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication me
Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service
Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may
Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networ
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adapti
MegaRAC Default Credentials Vulnerability
Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Comp
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypte
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate base
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authenticatio
Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.
The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the cl
A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vu
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the
django-mfa3 is a library that implements multi factor authentication for the django web framework. It achieves this by m
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and inform
Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password conf
A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown pa
A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown funct
A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of th
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started