A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an
The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious applicati
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A m
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attack
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attack
Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before versio
A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safa
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in Wi
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign a
A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authen
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to interce
In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentica
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even th
In Versa Director, the un-authentication request found.
The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows
Roomer is a discord bot cog (extension) which provides automatic voice channel generation as well as private voice and t
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malici
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control c
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and P
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass logi
Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access int
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unautho
There is a Permission verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of t
Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker c
A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specif
The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can u
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A person with physical access
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2
An issue in the authentication mechanism in Nong Ge File Explorer v1.4 unauthenticated allows to access sensitive data.
ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the S
Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted applica
An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information w
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-mi
Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial
Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of servi
Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.
Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started