CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,372 vulnerabilities with CWE-287
CVE-2015-6280
Cisco IOS 15.2-15.5 and IOS XE 3.6E-3.14S - Improper Authentication via SSHv2 RSA
CVE-2015-5998
Impero Education Pro < 5008 - Improper Authentication via Hardcoded Credential
CVE-2015-6266
Cisco Identity Services Engine 1.2(0.899) - Information Disclosure via Guest Portal Uploaded HTML Documents
CVE-2015-3775
Apple OS X <10.10.5 - Privilege Escalation
CVE-2015-1486
Symantec Endpoint Protection Manager <12.1-RU6-MP1 - Auth Bypass
CVE-2015-2978
Webservice-DIC yoyaku_v41 - Auth Bypass
CVE-2015-4453
OpenEMR 2.x-4.x - Unauthenticated Authentication Bypass via ignoreAuth Parameter
CVE-2015-1330
unattended-upgrades <0.86.1 - Man-in-the-Middle
CVE-2015-3457
Magento CE/EE <1.9.1.0-1.14.1.0 - Auth Bypass
CVE-2015-2117
HP TippingPoint SMS and vSMS < 4.2 - Unauthenticated Remote Code Execution via JBoss RMI
CVE-2015-2823
Siemens WinCC < 13.0 - Improper Authentication via Password Hash
CVE-2015-0198
IBM General Parallel File System 3.4-3.4.0.32, 3.5-3.5.0.24, 4.1-4.1.0.7 - Unauthenticated Remote Code Execution
CVE-2015-0670
Cisco Small Business IP Phones SPA 300/500 7.5.5 - Unauthenticated Remote Audio Stream Access
CVE-2015-0653
Cisco Expressway/TelePresence Unauthenticated Authentication Bypass via Crafted Login
CVE-2015-0607
Cisco IOS - Authentication Bypass via Invalid AAA Return Code Handling
CVE-2015-2047
TYPO3 4.3.0-4.3.14, 4.4.0-4.4.15, 4.5.0-4.5.39, 4.6.0-4.6.18 - Authentication Bypass via RSAAuth
CVE-2015-2033
Infoblox NetMRI < 6.8.2.11 - Remote Code Execution via Anyterm Daemon
CVE-2014-125060 HIGH
collabcal < 2014-12-09 - Improper Authentication in handleGet Function
CVSS 7.3
CVE-2014-9320 CRITICAL
SAP BusinessObjects Edge 4.1 - Privilege Escalation
CVSS 9.8
CVE-2014-3879 CRITICAL
FreeBSD < 9.2 - Authentication Bypass via Missing Policy Include Directive
CVSS 9.8
CVE-2014-4198 CRITICAL
BS-Client Private Client <2.6 - Auth Bypass
CVSS 9.1
CVE-2014-9753 CRITICAL
ATutor < 2.2 - Unauthenticated Authentication Bypass via auto_login Parameter
CVSS 9.8
CVE-2014-8347 HIGH
Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04 - Authentication Bypass via MatchPasswordData Function
CVSS 7.8
CVE-2014-5081 CRITICAL
sphider < 1.3.6, sphider-pro < 3.2, sphider-plus < 3.2 - Authentication Bypass
CVSS 9.8
CVE-2014-2651 CRITICAL
Unify OpenStage/OpenScape Desk Phone IP <V3 R3.11.0 - Auth Bypass
CVSS 9.8
Details
Vulnerabilities 4,372
Exploit Likelihood High