Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden share
SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with
An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP pac
An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.0
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same s
UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostnam
Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3
Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in the aff
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proce
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers
A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate sessio
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty val
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect cont
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attack
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's ini
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service p
When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficie
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network a
Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerabilit
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthentica
Evernote before 5.5.1 has insecure PIN storage
An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial program
There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient auth
There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient auth
An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. An attacker can bypass the password r
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. When biometric authentication is disa
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated
HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings suc
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user t
There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the i
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to d
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to d
The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical acce
Improper authentication in subsystem for Intel (R) LED Manager for NUC before version 1.2.3 may allow privileged user to
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.
ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker o
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConn
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-p
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not
BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Rem
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started