The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to
Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to cr
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack.
TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resu
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiF
CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authe
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ss
InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Del
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalon
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, r
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Dat
NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and dele
xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not bein
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password le
A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the
Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-midd
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physica
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-P
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerabili
An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Se
IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous user
An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to
On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authenticatio
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality al
A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical re
Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerabi
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0
Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions e
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express
A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated
In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of
Comcast XFINITY WiFi Home Hotspot devices allow remote attackers to spoof the identities of Comcast customers via a forg
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Net
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, conf
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to byp
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations
MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and dele
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started