The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status
Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymou
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without bein
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie pois
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security b
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulner
The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the prod
SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstance
Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these se
Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application,
Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were acce
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li
Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vu
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted
The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API com
An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86
Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerabil
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware vers
A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to acces
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG
On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console
A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-conne
The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vul
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fi
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allo
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable
Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login i
Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication usin
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitL
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted f
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sen
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly op
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with n
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could u
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication
Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading t
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrate
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started