CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,376 vulnerabilities with CWE-287
CVE-2011-0392
Cisco TelePresence Recording Server 1.6.x - Unauthenticated XML-RPC Interface Access
CVE-2011-0384
Cisco TelePresence Multipoint Switch Software 1.0.x-1.6.x - Unauthenticated Remote Code Execution
CVE-2011-0383
Cisco TelePresence Recording Server and Multipoint Switch - Unauthenticated Remote Code Execution
CVE-2011-0380
Cisco TelePresence Manager 1.2.x-1.6.x - Unauthenticated Authentication Bypass via Malformed SOAP Request
CVE-2011-0453
F-Secure Internet Gatekeeper for Linux 3.x < 3.03 - Unauthenticated Access Log Exposure via Admin UI Port
CVE-2011-0091
Microsoft Windows Server 2008 R2 & Windows 7 - Info Disclosure
CVE-2011-0039
Microsoft Windows XP/Server 2003 - Privilege Escalation
CVE-2011-0920
IBM Lotus Domino - Authentication Bypass and Remote Code Execution via UNC Share Pathname
CVE-2011-0688
Symantec Antivirus Corporate Edition 10.x < 10.1 MR10 - Remote Code Execution via Crafted TCP Messages
CVE-2011-0489
Objectivity/DB 10.0 - Unauthenticated Administrative Command Execution via Lock Server or Advanced Multithreaded Server
CVE-2010-2496 MEDIUM
cluster_glue < 1.0.6 and pacemaker < 1.1.3 - Password Exposure via Command Line Parameters
CVSS 5.5
CVE-2010-4690
Cisco ASA 5500 <8.3.2 - Info Disclosure
CVE-2010-4591
IBM Lotus Mobile Connect < 6.1.4 - Improper Authentication via LTPA Token Persistence
CVE-2010-4573
VMware ESXi 4.1 - Improper Authentication via Modified sfcb.cfg
CVE-2010-3905
Eucalyptus 2.0.0-2.0.1 - Unauthenticated Privilege Escalation via Password Reset Feature
CVE-2010-4333
Pointter PHP Micro-Blogging Social Network 1.8 - Unauthenticated Privilege Escalation via Cookie Manipulation
CVE-2010-4332
Pointter PHP Content Management System 1.0 - Unauthenticated Authentication Bypass via Cookie Manipulation
CVE-2010-4481
phpMyAdmin < 3.4.0-beta1 - Unauthenticated Sensitive Information Exposure via phpinfo.php
CVE-2010-4488
Google Chrome < 8.0.552.214 - Denial of Service via HTTP Proxy Authentication
CVE-2010-4478 CRITICAL
OpenSSH < 5.6 - Unauthenticated Authentication Bypass via J-PAKE Protocol
CVSS 9.8
CVE-2010-4252
OpenSSL < 1.0.0c - Improper Authentication via J-PAKE Parameter Validation Bypass
CVE-2010-4279
Pandora FMS < 3.1 - Unauthenticated Authentication Bypass via Empty loginhash_pwd
CVE-2010-3868
Red Hat Certificate System 7.3 and 8 and Dogtag Certificate System - Unauthenticated SCEP One-Time PIN Disclosure
CVE-2010-4232
Camtron CMNC-200 Firmware 1.102A-008 - Unauthenticated Authentication Bypass via Double Slash URI
CVE-2010-1838
Apple Mac OS X 10.5.8 and 10.6.x < 10.6.5 - Unauthenticated Authentication Bypass via Disabled Mobile Account
Details
Vulnerabilities 4,376
Exploit Likelihood High