Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-04-15 CVE-2020-7276 Improper Authentication vulnerability in Mcafee Endpoint Security
Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool.
local
low complexity
mcafee CWE-287
6.7
2020-04-13 CVE-2020-8148 Improper Authentication vulnerability in UI Cloud KEY Gen2 and Cloud KEY Gen2 Plus
UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicious API request.
network
low complexity
ui CWE-287
5.3
2020-04-10 CVE-2020-1801 Improper Authentication vulnerability in Huawei Mate 30 Firmware and Mate 30 PRO Firmware
There is an improper authentication vulnerability in several smartphones.
local
low complexity
huawei CWE-287
5.5
2020-04-08 CVE-2020-1637 Improper Authentication vulnerability in Juniper Junos
A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy.
network
low complexity
juniper CWE-287
6.5
2020-04-08 CVE-2020-1618 Improper Authentication vulnerability in Juniper Junos
On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password.
low complexity
juniper CWE-287
6.8
2020-04-08 CVE-2018-21062 Improper Authentication vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software.
low complexity
google CWE-287
4.6
2020-04-08 CVE-2018-21038 Improper Authentication vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x) software.
network
low complexity
google CWE-287
critical
9.8
2020-04-08 CVE-2017-18646 Improper Authentication vulnerability in Google Android
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software.
low complexity
google CWE-287
4.6
2020-04-07 CVE-2017-18654 Improper Authentication vulnerability in Google Android 6.0/7.0/7.1
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software.
network
low complexity
google CWE-287
7.5
2020-04-07 CVE-2016-11042 Improper Authentication vulnerability in Google Android 5.0/5.1/6.0
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software.
network
low complexity
google CWE-287
7.5