FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform
There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not veri
A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is dis
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an under
TRENDnet TS-S402 has a backdoor to enable TELNET.
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configur
An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated un
An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The S
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can
In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the roo
Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in Applica
Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 before 2017-01-06, WNR
An issue was discovered in Foxit E-mail advertising system before September 2018. It allows authentication bypass and in
An issue was discovered in Foxit PhantomPDF before 8.3.10. It has mishandling of cloud credentials, as demonstrated by G
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum P
An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pa
This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive informat
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets with
jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This lead
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed ser
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1
In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's acc
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow
In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates d
The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application
Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products a
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoin
omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. Th
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware vers
A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to acces
Evernote prior to 5.5.1 has insecure password change
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gai
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of per
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to cr
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2
Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentic
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started