Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-03-05 CVE-2020-8994 Improper Authentication vulnerability in MI Mdz-25-Dt Firmware 1.34.36/1.40.14
An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14.
low complexity
mi CWE-287
6.8
2020-03-04 CVE-2020-8664 Improper Authentication vulnerability in Cncf Envoy 1.13.0
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.
network
low complexity
cncf CWE-287
5.3
2020-03-04 CVE-2020-5536 Improper Authentication vulnerability in Plathome Openblocks IOT VX2 Firmware
OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to bypass authentication and to initialize the device via unspecified vectors.
low complexity
plathome CWE-287
8.8
2020-03-02 CVE-2018-15819 Improper Authentication vulnerability in Easyio 30P Firmware 2.0.5.16
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
network
low complexity
easyio CWE-287
7.5
2020-03-02 CVE-2019-20489 Improper Authentication vulnerability in Netgear Wnr1000 Firmware 1.1.0.54
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices.
network
low complexity
netgear CWE-287
critical
9.8
2020-02-27 CVE-2020-3923 Improper Authentication vulnerability in Tonnet products
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism.
network
low complexity
tonnet CWE-287
critical
9.8
2020-02-25 CVE-2019-5165 Improper Authentication vulnerability in Moxa Awk-3131A Firmware 1.13
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13.
network
low complexity
moxa CWE-287
7.2
2020-02-24 CVE-2018-14705 Improper Authentication vulnerability in Drobo 5N2 Firmware 4.0.5
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation.
network
low complexity
drobo CWE-287
critical
9.8
2020-02-24 CVE-2019-20481 Improper Authentication vulnerability in Miele XGW 3000 Zigbee Gateway Firmware
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password.
network
low complexity
miele CWE-287
critical
9.8
2020-02-24 CVE-2019-15299 Improper Authentication vulnerability in Centreon web
An issue was discovered in Centreon Web through 19.04.3.
network
low complexity
centreon CWE-287
8.8