CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (5,056)
page 62 of 253| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-26326 | Hig | 0.57 | 8.8 | 0.02 | Feb 28, 2025 | A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain total control of the remote system by guessing a weak password. The problem occurs because these add-ons accept… | ||
| CVE-2024-57046 | Hig | 0.57 | 8.8 | 0.02 | Feb 18, 2025 | A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication. | ||
| CVE-2024-46434 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2025 | Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP request. | ||
| CVE-2024-12919 | Cri | 0.57 | 9.8 | 0.01 | Jan 14, 2025 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the… | ||
| CVE-2024-1609 | Hig | 0.57 | — | 0.00 | Dec 25, 2024 | In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation. | ||
| CVE-2024-0130 | Hig | 0.57 | 8.8 | 0.00 | Dec 6, 2024 | NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of this vulnerability might lead to… | ||
| CVE-2024-47533 | Cri | 0.57 | 9.8 | 0.04 | Nov 18, 2024 | Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows… | ||
| CVE-2023-29117 | Hig | 0.57 | 8.8 | 0.00 | Nov 5, 2024 | Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system. | ||
| CVE-2023-22650 | Hig | 0.57 | 8.8 | 0.01 | Oct 16, 2024 | A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which… | ||
| CVE-2024-38139 | Hig | 0.57 | 8.7 | 0.01 | Oct 15, 2024 | Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-45148 | Hig | 0.57 | 8.8 | 0.01 | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauthorized access without… | ||
| CVE-2024-41589 | Hig | 0.57 | 8.8 | 0.00 | Oct 3, 2024 | DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests. | ||
| CVE-2024-41929 | Hig | 0.57 | 8.8 | 0.01 | Sep 18, 2024 | Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | ||
| CVE-2024-38225 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2024 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | ||
| CVE-2024-45346 | Hig | 0.57 | 8.8 | 0.00 | Aug 28, 2024 | The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security… | ||
| CVE-2024-42038 | Hig | 0.57 | 8.8 | 0.00 | Aug 8, 2024 | Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability. | ||
| CVE-2024-39340 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versions include UTM 11.5 through 12.6.4 and Reseller Preview… | ||
| CVE-2024-6397 | Cri | 0.57 | 9.8 | 0.01 | Jul 11, 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unauthenticated attackers to log… | ||
| CVE-2024-23767 | Hig | 0.57 | 8.8 | 0.00 | Jun 26, 2024 | An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations. | ||
| CVE-2024-36264 | Cri | 0.57 | 9.8 | 0.01 | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this… |
- risk 0.57cvss 8.8epss 0.02
A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain total control of the remote system by guessing a weak password. The problem occurs because these add-ons accept…
- risk 0.57cvss 8.8epss 0.02
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
- risk 0.57cvss 8.8epss 0.01
Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP request.
- risk 0.57cvss 9.8epss 0.01
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the…
- risk 0.57cvss —epss 0.00
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
- risk 0.57cvss 8.8epss 0.00
NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of this vulnerability might lead to…
- risk 0.57cvss 9.8epss 0.04
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows…
- risk 0.57cvss 8.8epss 0.00
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which…
- risk 0.57cvss 8.7epss 0.01
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauthorized access without…
- risk 0.57cvss 8.8epss 0.00
DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.
- risk 0.57cvss 8.8epss 0.01
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- risk 0.57cvss 8.8epss 0.01
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.00
The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security…
- risk 0.57cvss 8.8epss 0.00
Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- risk 0.57cvss 8.8epss 0.01
The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versions include UTM 11.5 through 12.6.4 and Reseller Preview…
- risk 0.57cvss 9.8epss 0.01
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unauthenticated attackers to log…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.
- risk 0.57cvss 9.8epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this…