On this page

CWE-287: Improper Authentication

Weakness Summary

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

  • Canonical source: MITRE CWE-287 (opens in a new tab)
  • Published Atomicorp CVE observations: 38
  • Distinct affected products in those observations: 38
  • Active Atomicorp rules associated with this weakness: 71

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2025-55169WeGIA - Directory TraversalwegiaAttack Blocked by Atomicorp340007 , 344360
CVE-2026-49869Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilterkestraAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2013-2681Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmwareAttack Blocked by Atomicorp392301
CVE-2013-7137Burden 1.8 - Authentication BypassburdenAttack Blocked by Atomicorp390727 , 392301 , 392648
CVE-2018-17153Western Digital MyCloud NAS - Authentication Bypassmy cloud wdbctl0020hwt firmwareAttack Blocked by Atomicorp344363
CVE-2018-17431Comodo Unified Threat Management Web Console - Remote Code Executionunified threat management firewallAttack Blocked by Atomicorp344361 , 344362 , 344364 , 390722
CVE-2018-3810Oturia WordPress Smart Google Code Inserter <3.5 - Authentication Bypasssmart google code inserterAttack Blocked by Atomicorp380026
CVE-2019-13372D-Link Central WiFi Manager CWM(100) - Remote Code Executioncentral wifimanagerAttack Blocked by Atomicorp344370
CVE-2019-1937Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilitiesintegrated management controller supervisorAttack Blocked by Atomicorp344362 , 344363 , 344370 , 345493 , 350147 , 360151 , 390724 , 390727 , 392301 , 392648
CVE-2020-8771WordPress Time Capsule < 1.21.16 - Authentication Bypasswp time capsuleAttack Blocked by Atomicorp392301
CVE-2021-1472Cisco Small Business RV Series - OS Command Injectionrv160 firmwareAttack Blocked by Atomicorp340014 , 340149 , 344364 , 344366 , 344370 , 350147
CVE-2021-24527Profile Builder < 3.4.9 - Improper Authenticationprofile builderAttack Blocked by Atomicorp340130
CVE-2021-25281SaltStack Salt <3002.5 - Auth BypasssaltAttack Blocked by Atomicorp340007
CVE-2023-30869Easy Digital Downloads - Privilege Escalationeasy digital downloadsDetected by Atomicorp377360
CVE-2023-34124SonicWall GMS and Analytics Web Services - Shell InjectionanalyticsAttack Blocked by Atomicorp340017 , 360148 , 380123
CVE-2024-0799Arcserve Unified Data Protection - Authentication BypassudpAttack Blocked by Atomicorp391213
CVE-2024-7593Ivanti vTM - Authentication Bypassvirtual traffic managerAttack Blocked by Atomicorp392301
CVE-2025-61882Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Executionconcurrent processingAttack Blocked by Atomicorp391213
CVE-2026-11387SMS Alert – SMS & OTP for WooCommerce - Privilege Escalationsms-alertDetected by Atomicorp377360
CVE-2026-48528Metacat has an unauthenticated SQL injection vulnerabilitymetacatAttack Blocked by Atomicorp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82329JFrog Artifactory Access Blank Join Key Authentication BypassartifactoryAttack Blocked by Atomicorp300022
CVE-2013-4863MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmwareAttack Blocked by Atomicorp330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2018-12613PhpMyAdmin <4.8.2 - Local File InclusionphpmyadminAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2018-7358ZTE ZXHN H168N - Improper Access Restrictionszxhn h168n firmwareAttack Blocked by Atomicorp330791 , 334168 , 340152
CVE-2020-24579D-Link DSL 2888a - Authentication Bypass/Remote Command Executiondsl2888a firmwareAttack Blocked by Atomicorp344360 , 347009 , 390904 , 392301
CVE-2022-41678Apache ActiveMQ < 5.16.5/5.17.3 - Remote Code ExecutionactivemqAttack Blocked by Atomicorp330925
CVE-2023-4415Ruijie RG-EW1200G Router Background - Login Bypassrg-ew1200g firmwareAttack Blocked by Atomicorp392301
CVE-2018-12455Intelbras NPLUG 1.0.0.14 - Authentication BypassnplugAttack Blocked by Atomicorp390716
CVE-2025-27621UpTrain has a Constant Default API KeyuptrainAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2015-6401Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapterAttack Blocked by Atomicorp333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2018-19458PHP Proxy 3.0.3 - Local File Inclusionphp-proxyAttack Blocked by Atomicorp340162 , 340165 , 344360 , 347009
CVE-2023-0905Employee Task Management System v1.0 - Broken Authenticationemployee task management systemAttack Blocked by Atomicorp344365 , 344370 , 345493 , 350147
CVE-2025-61884Oracle E-Business Suite - Server-Side Request ForgeryconfiguratorAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 340165 , 341256 , 342259 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2012-1258Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilitiesscrutinizer netflow &amp; sflow analyzerAttack Blocked by Atomicorp340003 , 340147 , 340148 , 340156 , 341245 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585 , 390727 , 392301 , 392648
CVE-2021-39165Cachet <=2.3.18 - SQL InjectioncachetAttack Blocked by Atomicorp340145 , 340156 , 341145 , 380026 , 380122
CVE-2025-32815NetMRI < 7.6.1 - Authentication Bypass via Hardcoded CredentialsnetmriAttack Blocked by Atomicorp344360 , 390709 , 390722
CVE-2025-53771Microsoft SharePoint Server - Authentication Bypass (ToolShell)sharepoint serverAttack Blocked by Atomicorp330906 , 350147
CVE-2022-28666Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Updatecustom product tabs for woocommerceAttack Blocked by Atomicorp392301

Associated Atomicorp WAF Rules

RuleStatusBehavior
300022Activedisruptive (deny)
330791Activedisruptive (deny)
330906Activedisruptive (deny)
330925Activedisruptive (deny)
333141Activedisruptive (deny)
334168Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
340003Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340121Activedisruptive (deny)
340130Activedisruptive (deny)
340144Activedisruptive (deny)
340145Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340149Activedisruptive (deny)
340152Activedisruptive (deny)
340156Activedisruptive (deny)
340157Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
340193Activedisruptive (deny)
341145Activedisruptive (deny)
341245Activedisruptive (deny)
341256Activedisruptive (deny)
341266Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344362Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
345493Activenon-disruptive (pass)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
360151Activedisruptive (deny)
377360Activenon-disruptive (pass)
380026Activedisruptive (deny)
380122Activedisruptive (deny)
380123Activedisruptive (deny)
390572Activedisruptive (deny)
390585Activedisruptive (deny)
390636Activedisruptive (deny)
390709Activedisruptive (deny)
390716Activedisruptive (deny)
390722Activedisruptive (deny)
390724Activedisruptive (deny)
390726Activedisruptive (deny)
390727Activedisruptive (deny)
390904Activedisruptive (deny)
391213Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
393655Activedisruptive (deny)
398021Activedisruptive (deny)
398022Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-114 (opens in a new tab) , CAPEC-115 (opens in a new tab) , CAPEC-151 (opens in a new tab) , CAPEC-194 (opens in a new tab) , CAPEC-22 (opens in a new tab) , CAPEC-57 (opens in a new tab) , CAPEC-593 (opens in a new tab) , CAPEC-633 (opens in a new tab) , CAPEC-650 (opens in a new tab) , CAPEC-94 (opens in a new tab)