CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,374 vulnerabilities with CWE-287
CVE-2013-5531
Cisco Identity Services Engine 1.x - Unauthenticated Authentication Bypass via Crafted TCP Session
CVE-2013-5511
Cisco ASA Software 8.2-9.1 Unauthenticated Authentication Bypass via ASDM
CVE-2013-5510
Cisco ASA <9.1(2.5) Unauthenticated LDAP Authentication Bypass
CVE-2013-4824
HP Intelligent Management Center and IMC Service Operation Management Software Module - Authentication Bypass
CVE-2013-3610
ASUS RT-N10E Firmware < 2.0.0.24 - Unauthenticated Administrator Password Exposure via QIS_finish.htm
CVE-2013-5163
Apple Mac OS X <10.8.5 - Auth Bypass
CVE-2013-5944
Siemens SCALANCE X-200 Series <4.5.0 & X-200IRT <5.1.0 - Unauthenticated Admin Access
CVE-2013-3417
Cisco Video Surveillance Operations Manager - Unauthenticated Video Feed Access via Crafted URL
CVE-2013-5200
Open-Xchange AppSuite <7.0.2-7.2.2 - Info Disclosure
CVE-2013-5119
Zimbra Collaboration Suite <6.0.16 - Info Disclosure
CVE-2013-1443
Django 1.4-1.4.8 1.5-1.5.4 1.6-1.6 beta 4 - Denial of Service via Long Password Hashing
CVE-2013-3473
Cisco Prime Central for Hosted Collaboration Solution Assurance < 9.1.1 - Credential Exposure
CVE-2013-5497
Cisco Intrusion Prevention System - Denial of Service via Crafted Management-Interface Connection Request
CVE-2013-3613
Dahua DVR - Unauthenticated Remote Access via UPnP Replay Attack
CVE-2013-3039
IBM Rational Requirements Composer <4.0.4 - Info Disclosure
CVE-2013-4061
IBM Rational Policy Tester 8.5 - Authenticated Authorization Bypass for Authentication Host Changes
CVE-2013-3466
Cisco Secure Access Control Server < 4.2.1.15.11 - Remote Code Execution via EAP-FAST Packet Parsing
CVE-2013-3586
Samsung Smart Viewer - Unauthenticated Authentication Bypass via SessionID Cookie
CVE-2013-4958
Puppet Enterprise <3.0.1 - Privilege Escalation
CVE-2013-2157
OpenStack Keystone >=2012.2 <2012.2.4 - Unauthenticated Authentication Bypass via Empty LDAP Password
CVE-2013-3659
NTT DOCOMO overseas usage 2.0.0-2.0.4 - Improper Authentication via Wi-Fi Connection
CVE-2013-2993
IBM WebSphere Commerce <6.0.0.11 & <7.0.0.7 - Auth Bypass
CVE-2013-2056
Red Hat Satellite 5.3-5.5 - Improper Authentication in Inter-Satellite Sync
CVE-2013-2245
Moodle <= 2.1.10, 2.2.x < 2.2.11, 2.3.x < 2.3.8, 2.4.x < 2.4.5, 2.5.x < 2.5.1 - Information Disclosure
CVE-2013-3431
Cisco Video Surveillance Manager < 7.0.0 - Unauthenticated Information Disclosure via VSMC Monitoring Pages
Details
Vulnerabilities 4,374
Exploit Likelihood High