CWE-287: Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
How it's found
Improper Authentication describes a general pattern rather than a single fixed bug. Testers use a mix of static analysis and manual code review to find where a target's code matches this pattern, then confirm exploitability by hand.
Consequences
- Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands: This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
Mitigations
- Architecture and Design: Use an authentication framework or library such as the OWASP ESAPI Authentication feature.
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is CWE-287?
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
How do you find Improper Authentication?
Improper Authentication describes a general pattern rather than a single fixed bug. Testers use a mix of static analysis and manual code review to find where a target's code matches this pattern, then confirm exploitability by hand.
What is the impact of CWE-287?
Read Application Data, Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands: This weakness can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.
Does TurboPentest test for Improper Authentication?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related CWEs
- Pillar weaknessCWE-284: Improper Access Control
- Variant weaknessCWE-259: Use of Hard-coded Password
- Base weaknessCWE-301: Reflection Attack in an Authentication Protocol
- Base weaknessCWE-309: Use of Password System for Primary Authentication
- Class weaknessCWE-345: Insufficient Verification of Data Authenticity
- Compound weaknessCWE-384: Session Fixation
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest