An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 becau
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitL
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user
The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain un
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood gluc
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wire
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Pl
A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscre
There is an improper authentication vulnerability in some Huawei AP products before version V200R009C00SPC800. Due to th
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.10465
Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 ma
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by chang
This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constru
An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) ca
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, w
The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration f
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) applicatio
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenti
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allo
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions
Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of e
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energ
A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to do
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAP
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could explo
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could byp
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted f
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating u
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacke
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks wh
E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does
An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2.
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authenticatio
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may b
A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated,
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a val
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started