Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-03-20 CVE-2020-1878 Improper Authentication vulnerability in Huawei Oxfords-An00A Firmware
Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability.
local
low complexity
huawei CWE-287
5.5
2020-03-20 CVE-2020-1864 Improper Authentication vulnerability in Huawei Secospace Antiddos8000 Firmware
Some Huawei products have a security vulnerability due to improper authentication.
network
high complexity
huawei CWE-287
8.1
2020-03-20 CVE-2020-1794 Improper Authentication vulnerability in Huawei Mate 20 Firmware and Mate 30 PRO Firmware
There is an improper authentication vulnerability in several smartphones.
low complexity
huawei CWE-287
4.6
2020-03-20 CVE-2020-1793 Improper Authentication vulnerability in Huawei Mate 20 Firmware and Mate 30 PRO Firmware
There is an improper authentication vulnerability in several smartphones.
low complexity
huawei CWE-287
4.6
2020-03-19 CVE-2020-10669 Improper Authentication vulnerability in Canon OCE Colorwave 500 Firmware 4.0.0.0
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp.
network
low complexity
canon CWE-287
7.5
2020-03-19 CVE-2020-4205 Improper Authentication vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked.
network
low complexity
ibm CWE-287
6.3
2020-03-16 CVE-2020-6988 Improper Authentication vulnerability in Rockwellautomation products
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller.
network
low complexity
rockwellautomation CWE-287
7.5
2020-03-16 CVE-2018-13060 Improper Authentication vulnerability in Easyappointments Easy!Appointments
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
network
low complexity
easyappointments CWE-287
6.5
2020-03-15 CVE-2020-10594 Improper Authentication vulnerability in Styria Django-Rest-Framework-Json web Tokens 1.15.0
An issue was discovered in drf-jwt 1.15.x before 1.15.1.
network
low complexity
styria CWE-287
critical
9.1
2020-03-12 CVE-2020-9064 Improper Authentication vulnerability in Huawei Honor V30 Firmware 10.0.1.135(C00E130R4P1)/10.1.0.212(C00E210R5P1)/Oxfordsan00A10.0.1.167(C00E166R4P1)
Huawei smartphone Honor V30 with versions earlier than OxfordS-AN00A 10.0.1.167(C00E166R4P1) have an improper authentication vulnerability.
local
low complexity
huawei CWE-287
5.5