Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can cr
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of a
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.
SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Window
IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication i
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generatio
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication,
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate
Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled
TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHO
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attac
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated,
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for us
Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that
HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earli
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access
Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is mis
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send"
An exploitable denial of service vulnerability exists in Insteon Hub running firmware version 1012. Leftover demo functi
In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of file
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager int
MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs to
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR
There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote att
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism i
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Aff
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data v
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application
If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can o
A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive informatio
In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authenticatio
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication
An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authenticat
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to
The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 bef
The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an auth
The 'Find Phone' function in some Huawei smart phones with software earlier than Duke-L09C10B186 versions, earlier than
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authenticati
In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a m
Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can al
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started