The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue
Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin()
Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 befor
An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed wi
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new
AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 has
An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier)
An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerabil
Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in
RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF user
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vu
SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing m
Envoy is a cloud-native high-performance edge/middle/service proxy. In Envoy version 1.17.0 an attacker can bypass authe
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an a
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s)
A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running B
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in th
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle a
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres
Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerabili
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentica
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulner
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh
An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Mod
Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacke
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authenticatio
IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to subm
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an
A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access ri
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstance
Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the appli
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profi
Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN,
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configu
Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Expr
pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticat
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password req
Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated end
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secon
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started