Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-02-22 CVE-2020-8862 Improper Authentication vulnerability in Dlink Dap-2610 Firmware
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers.
low complexity
dlink CWE-287
8.8
2020-02-22 CVE-2020-8861 Improper Authentication vulnerability in Dlink Dap-1330 Firmware 1.00.B21/1.10B01
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range extenders.
low complexity
dlink CWE-287
8.8
2020-02-19 CVE-2020-3944 Improper Authentication vulnerability in VMWare Vrealize Operations 6.6.0/6.7.0
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass.
network
low complexity
vmware CWE-287
8.6
2020-02-19 CVE-2011-2054 Improper Authentication vulnerability in Cisco products
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct.
network
high complexity
cisco CWE-287
7.5
2020-02-18 CVE-2014-3879 Improper Authentication vulnerability in Freebsd
OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login (1) without a password or (2) with an incorrect password.
network
low complexity
freebsd CWE-287
critical
9.8
2020-02-18 CVE-2013-4454 Improper Authentication vulnerability in Getbutterfly Portable-PHPmyadmin 1.4.1
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities
network
low complexity
getbutterfly CWE-287
critical
9.1
2020-02-18 CVE-2020-1842 Improper Authentication vulnerability in Huawei products
Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability.
low complexity
huawei CWE-287
6.8
2020-02-18 CVE-2020-1812 Improper Authentication vulnerability in Huawei P30 Firmware
HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability.
local
low complexity
huawei CWE-287
7.8
2020-02-18 CVE-2020-1789 Improper Authentication vulnerability in Huawei products
Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentication vulnerability.
low complexity
huawei CWE-287
6.8
2020-02-17 CVE-2015-6922 Improper Authentication vulnerability in Kaseya Virtual System Administrator
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.
network
low complexity
kaseya CWE-287
critical
9.8