In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio
October is a Content Management System (CMS) and web platform built on the the Laravel PHP Framework. In affected versio
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower use
An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user t
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, web
Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controll
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability
An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is v
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their
A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(
Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, cou
Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escal
An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability relate
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated
An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker wi
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physic
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor w
In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin
1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure
Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were acce
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information a
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users withi
Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in th
Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect
The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote atta
An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `Op
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authenticat
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthoriz
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` func
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacke
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacke
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-th
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired p
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when t
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout syste
The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settin
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report
A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerabilit
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by
omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original passw
Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vu
Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authen
Bot Framework SDK Information Disclosure Vulnerability
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started