Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3.
In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnera
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile applic
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exis
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in
Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 seri
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not pr
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidat
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not co
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the Auth
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas
Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Man
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be chan
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (V4.5.0). Affected devices fai
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthe
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of t
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdra
Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto,
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect s
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability
There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, pas
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of th
Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles
TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. Th
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an a
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNA
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a vict
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remot
Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protectio
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could a
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started